All Apps and Add-ons

Running Browsing History Analysis on Windows with just a Universal Forwarder

realgandy
Explorer

Can you give details of how to get this to work on Windows that is only running a universal forwarder? I have installed a local copy of python, but the log gives the following errors:

 05-02-2014 16:17:43.474 +0100 ERROR ExecProcessor - message from "python "C:\Program Files\SplunkUniversalForwarder\etc\apps\browsers\bin\monitor.py""   File "C:\Program Files\SplunkUniversalForwarder\etc\apps\browsers\bin\monitor.py", line 60
05-02-2014 16:17:43.474 +0100 ERROR ExecProcessor - message from "python "C:\Program Files\SplunkUniversalForwarder\etc\apps\browsers\bin\monitor.py""     except Exception,e:
05-02-2014 16:17:43.474 +0100 ERROR ExecProcessor - message from "python "C:\Program Files\SplunkUniversalForwarder\etc\apps\browsers\bin\monitor.py""                     ^
05-02-2014 16:17:43.474 +0100 ERROR ExecProcessor - message from "python "C:\Program Files\SplunkUniversalForwarder\etc\apps\browsers\bin\monitor.py"" SyntaxError: invalid syntax

Any thoughts on this please?

Thanks

0 Karma

MarioM
Motivator

the problem is that the monitor.py use 2 splunk python libraries:

import splunk.bundle as bundle
import splunk.util as util

And the universal forwarder doesnot have python or those librarie which you can find in a full splunk installation:

util.py

splunk_home\lib\python2.7\ctypes\

bundle.py

splunk_home\lib\python2.7\site-packages\splunk\clilib\
0 Karma

psbailey86
Explorer

I am having this exact issue with the latest version. Were you ever able to find a fix for this using a Windows Universal Forwarder?

Thanks!

MarioM
Motivator

you could try by putting those util.py... and bundle.py... in splunk_home\etc\apps\browsers\bin\

0 Karma

realgandy
Explorer

Are you saying it can't be done then.

Am I right to assume that those libraries require the full splunk installation for this app to work?

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...