All Apps and Add-ons

Why is a bash script running if I have disabled the input stanza?

stuartjbowell
Engager

I have been ingesting data from an Akamai WAF using the Akamai TA from SplunkBase. Once I have sorted all of the firewall issues and such with the team I have it working how I want it.

I have the TA installed on the HF and Search Peers of my Index Cluster with the base stanza in default/inputs.conf set to disabled. I have then created a light weight TA which just has the inputs.conf setup with the appropriate tokens, URL's etc and have that only on the HF.

The TA itself has a linux folder which contains a bash script that calls the Java app that makes the connection to the REST API. All good so far.

However, when I deployed the SplunkBase TA to the Indexers, it still tries to run the Java app even though I have the inputs stanza disabled.

Does Splunk run scripts in the linux folders (and I assume windows too) if it finds them? If so how do I disable them on the indexers but not on the HF? The SplunkBase TA also has props and transforms so I definitely want them on both the HF and Indexers.

Hope this makes sense and any help greatly appreciated?

Many thanks

0 Karma
1 Solution

maraman_splunk
Splunk Employee
Splunk Employee

looks like you did the right thing by separating the input into a inout app and removing inputs.conf from the TA you pushed everywhere. The original version ship it so that you know what kind of inout to expect for this TA.
if you have a scripted input, I think the only think you can play with is the interval, I dont see the disabled in the spec file ( link text) so if you dont need it at all just remove it or comment it out.

View solution in original post

0 Karma

maraman_splunk
Splunk Employee
Splunk Employee

looks like you did the right thing by separating the input into a inout app and removing inputs.conf from the TA you pushed everywhere. The original version ship it so that you know what kind of inout to expect for this TA.
if you have a scripted input, I think the only think you can play with is the interval, I dont see the disabled in the spec file ( link text) so if you dont need it at all just remove it or comment it out.

0 Karma

stuartjbowell
Engager

Thanks for the comment @maraman_splunk . I have commented out the default/inputs.conf and removed the local/inputs.conf that I added and that seems to have done the trick. As many have told me since. There is no way to disable a Modular Input.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...