All Apps and Add-ons

Invalid key in stanza [Splunk_TA_f5_bigip_main]

gduggan1
Path Finder

I am running Splunk 6.3.3 and F5 TA 2.4.0 and getting the following error. Anyone seen this before? I am still indexing data from F5 so it can't be too critical....

Invalid key in stanza [Splunk_TA_f5_bigip_main] in /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/inputs.conf, line 12: start_by_shell (value: false).

btool debug
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/app.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/eventgen.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/eventtypes.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/f5_bigip_templates.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/inputs.conf
Invalid key in stanza [Splunk_TA_f5_bigip_main] in /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/inputs.conf, line 12: start_by_shell (value: false).
Did you mean 'source'?
Did you mean 'sourcetype'?
No spec file for: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/log_info.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/props.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/tags.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/transforms.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/web.conf

1 Solution

maikfischer
Engager

Hi,

as start_by_shell is an option for a script-stanza, try to rename the stanza "[Splunk_TA_f5_bigip_main]" to "[script://./bin/Splunk_TA_f5_bigip_main.py]".

regards,

Maik

View solution in original post

0 Karma

gduggan1
Path Finder

Thank you very much!

0 Karma

maikfischer
Engager

Hi,

as start_by_shell is an option for a script-stanza, try to rename the stanza "[Splunk_TA_f5_bigip_main]" to "[script://./bin/Splunk_TA_f5_bigip_main.py]".

regards,

Maik

0 Karma

jmantor
Path Finder

This stanza is still broken in version 2.5.0 of this app.
Could this get fixed upstream, please?

michael_kushma
Path Finder

Can we see the inputs.conf in question?

0 Karma

gduggan1
Path Finder

inputs.conf

[udp://9514]
disabled = false
connection_host=ip
sourcetype = f5:bigip:syslog

[tcp://9515]
disabled = false
connection_host=ip
sourcetype = f5:bigip:syslog

[Splunk_TA_f5_bigip_main]
start_by_shell = false

0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...