All Apps and Add-ons

Problem installing TA-uas_parser

psbailey86
Explorer

I am attempting to get this TA working but am encountering errors when trying to update the cache via the update_cache.py script. My Splunk servers do not have internet access so I installed this TA locally on my windows 7 machine where I have splunk installed as well to test with. I am encountering errors any way I try this. Any help would be greatly appreciated here this is just what I have needed for a project I am working on.

Errors I am getting:

running the following command from the command prompt in windows:
c:\$Splunk_home\etc\apps\TA-uas_parser\bin $Splunk_home\bin\python.exe update_cache.py

Error:
ImportError: No module named site

When installing python and running the command I get this:

c:\python.exe update_cache.py

File "update_cache.py", line 6
print "Cache data updated."
SyntaxError: invalid syntax

I really need to get this addon working it would help us out a ton!
Thanks in advance!

Tags (1)
0 Karma

pmccomb
Explorer

I am having this same issue. Is there an update for a windows machine?

0 Karma

dshpritz
SplunkTrust
SplunkTrust

Hey pmccomb,

Sorry, I haven't had a Windows system to test on. I'll try to get to it soon.

Dave

0 Karma

psbailey86
Explorer

Dave thanks for the response. I ended up installing this on a linux instance of Splunk and generated the cache file, and then copying it over to the other Splunk server. Not ideal but now it works and i was able to accomplish what I needed.

Thanks for the response.

0 Karma

dshpritz
SplunkTrust
SplunkTrust

Hello psbailey,

I'm Dave and TA-uas_parser is my fault.
I'm afraid I never tested the TA on a Windows install. I don't have a VM handy, but I can try to test it soon. As an alternative, you can also take a look at the TA-browscap addon, which performs a similar function, but uses a different library.

Thanks,

Dave

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...