All Apps and Add-ons

Not getting any data from Google Apps for Splunk

hlarimer
Communicator

I have set up the Google Apps for Splunk app and successfully went through the configuration steps, but I'm not seeing any data. There are 3 inputs set up that I believe were there by default (this app was already installed when I took over this instance), but I'm wondering if they are correct or if there are other inputs that needed to be added. Any tips on getting data in?

Tags (1)
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

After an extensive webex, I discovered that the modular input was configured with an UPPER CASE domain. The credential was configured with lower case domain. Due to case sensitivity of the filesystem (*nix), the credentials were not found since the file didn't exist with upper case.

RESOLUTION: I will be enforcing lower case programatically when looking for and creating the credential file.

Thanks for the remote session @hlarimer!

EDIT: v1.1.3 has the update. Let me know of any other issues! Thanks!

View solution in original post

alacercogitatus
SplunkTrust
SplunkTrust

After an extensive webex, I discovered that the modular input was configured with an UPPER CASE domain. The credential was configured with lower case domain. Due to case sensitivity of the filesystem (*nix), the credentials were not found since the file didn't exist with upper case.

RESOLUTION: I will be enforcing lower case programatically when looking for and creating the credential file.

Thanks for the remote session @hlarimer!

EDIT: v1.1.3 has the update. Let me know of any other issues! Thanks!

MuS
SplunkTrust
SplunkTrust

Nice hint @alacercogitatus! Will enforce the same in my modular inputs from now on - thanks.

0 Karma

hlarimer
Communicator

Thanks again for the help @alacercogitatus

0 Karma

ontkanin
Path Finder

Thanks @alacercogitatus

0 Karma

ontkanin
Path Finder

Doesn't work for me either. It used to work, but it looks like one of the Splunk upgrades broke it. Or at least that's what it looks like in my case.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

@ontkanin: contact me directly, I'll have a look. I'm working with @hlarimer this morning to debug this question.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...