All Apps and Add-ons

Splunk Add-on for F5 BIG-IP: Why am I unable to initialize the modular input?

stanhoener
Engager

Search peer has the following message: Unable to initialize modular input "Splunk_TA_f5_bigip_main" defined inside the app "Splunk_TA_f5-bigip": Unable to locate suitable script for introspection.

0 Karma

aagro
Path Finder

I have resovled this problem just only adding a comment for the stanza and attributes inside the config file inputs.conf.spec as showing below:

FILE => .../Splunk_TA_f5-bigip/README/inputs.conf.spec
# [Splunk_TA_f5_bigip_main://]

# nothing=nothing

Then restart splunk.

0 Karma

ragedsparrow
Contributor

I work with Stan here and I was able to fix this by doing the following:

  • I removed the README/inputs.conf.spec filefor the app (since we were deploying on index clusters, there were no need for the inputs.conf on these servers).
  • I also commented out the stanza for the input in the default/log_info.conf .

After I pushed these changes to the IDX cluster, we stopped receiving the error message.

payamhaddad
New Member

do u use Universal Forwarder to receive data from F5 ? based on syslog ?

then how you send them to indexers ?
is the TA working on indexers?

0 Karma

sbbadri
Motivator

That error might because of wrong installation or configuration.

Check below link for hardware and software requirements.

http://docs.splunk.com/Documentation/AddOns/released/F5BIGIP/Hardwareandsoftwarerequirements

Hope this helps .

0 Karma

stanhoener
Engager

getting the above error when f5-bigip is loaded on to our index cluster peers.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...