All Apps and Add-ons

Splunk for Cisco Security App Install error

ryanbyrdbasicre
Engager

I want to install Splunk for Cisco Security App

I used downloaded http://www.splunkbase.com/apps/All/4.x/App/app:Splunk+for+Cisco+Security and unzip/untared the file to /opt/splunk/etc/apps. I'm running splunk version 4.0.11, build 79031 on linux

then I chown the files to splunk and chmod them to 755

the I restart splunk (service splunk stop; service splunk start)

when i log into the web interface and click the Cisco Security App icon, I get a page with 3 javascript alert popups: Splunk encountered the following unknown module: "ConvertToDrilldownSearch" . The view may not load properly.

as well, in red, at the top of the screen is: Misconfigured view 'gc_overview' - Unknown parameter 'drilldown' is defined for module SimpleResultsTable. Make sure the parameter is specified in SimpleResultsTable.conf.

ideas?

Tags (2)
1 Solution

ziegfried
Influencer

Drilldown is a feature that was introduced in Splunk 4.1. Seems like the Cisco Security app uses this features in some views and hence is not compatible with 4.0.x. Your best bet is to upgrade your Splunk installation.

View solution in original post

ziegfried
Influencer

Drilldown is a feature that was introduced in Splunk 4.1. Seems like the Cisco Security app uses this features in some views and hence is not compatible with 4.0.x. Your best bet is to upgrade your Splunk installation.

Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...