All Apps and Add-ons

Verify that lookups installed with Splunk Security Essentials is present

tkreiner
Explorer

I have confirmed now that the app is no longer replicating the lookup files up to the indexer through bundle replication. However, when I use the Use Case pages, I'm seeing the error above in the Data Check panel. When I click on the Open in Search link, I see that it is using a REST call to determine if the lookup is available. However, the REST call is going against the search peers (which no longer have the replicated copy) and not against the local Splunk instance.

I traced the configurations back to the JSON files in appserver/static/components/data/samplesSearches and saw where that REST command was coded in the test values for each of the use cases. I appended "splunk_server=local" to each of the REST calls. After restarting Splunk, the Data Check panels were now reporting correctly.

Sample SPL command:
| rest /servicesNS/-/-/data//lookup-table-files splunk_server=local | eval blah=1, row=\"row\"| xyseries row title blah

SamHTexas
Builder

Where do I find this lookup & how do I verify it please?

0 Karma

SamHTexas
Builder

Does any good security person here know? My Security Essentials keeps asking for "Splunk Datasets add-on. Do I install it where the ES is installed ? 

Tags (1)
0 Karma

David
Splunk Employee
Splunk Employee

First, apologies for the delay. Somehow I'd turned off notifications for the app.

Second, thank you for the bug fix! I just pushed version 1.4.4 with the fix! As soon as it goes through review, you should be able to see the correction.

Thanks for the report (and the patience)!

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...