All Apps and Add-ons

Error while posting to url=/servicesNS/nobody/Splunk_CiscoSecuritySuite/css_setup/css_setup_endpoint/default

sec_team_albara
New Member

Cisco security suite application installed on splunk entreprise 7.2.3 (windows platfrom).
When trying to configure the application by checking "Enable Cisco ASA Dashboards ", I receive the following error:
Error while posting to url=/servicesNS/nobody/Splunk_CiscoSecuritySuite/css_setup/css_setup_endpoint/default

I modified $SPLUNK_HOME/etc/apps/Splunk_CiscoSecuritySuite/local/app.conf
[install]
is_configured = 1
Unfortunately, I still receive the same issue.

Your help is much appreciated

0 Karma

antlefebvre
Communicator

Not sure if this will work/apply for you. I did this with success on a ubuntu install (not windows) and entered true rather than 1. Splunk 7.2.5.

To do so, open etc/apps/Splunk_CiscoSecuriySuite/local/app.conf (or create it if it does not exist) and enter the following:

[install]
is_configured = true

You may need to restart Splunk after editing the config file. Splunk won't force you to view the setup screen once it recognizes the app is considered configured.

Original post here: https://answers.splunk.com/answers/12702/splunk-cisco-security-suite.html

0 Karma

lino_76
New Member

Following up from my previous post.

In effort move forward and save time, I decided to uninstall Splunk Version 7.2.3 and install (at random) Splunk version 6.5.2. I now can see Cisco Security Suite and installed it successfully without an errors.
Not sure if the app works beyond version 6.5.2 or before 7.2.3.

Hope this helps...

0 Karma

lino_76
New Member

I'm seeing the same error with my version of Splunk (version 7.3). Is there a solution for this error?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...