All Apps and Add-ons

is it compatible with splunk 6.4??

tp92222
Explorer

is it compatible with splunk 6.4?? if not any plans to update ???

0 Karma

LukeMurphey
Champion

I haven't tested it yet, but I would be very surprised if it failed to work. I'll do some testing tomorrow and post a comment here.

Update:

I tested it and it works fine. Let me know if you see any issues.

0 Karma

tp92222
Explorer

after adding rss feed ..i still see number of input as 0

Data inputs » TCP page

I am using 6.4.0

0 Karma

LukeMurphey
Champion

Can you try a couple of debugging steps? First, see if any errors or relevant messages are returned with this search:

(index=main sourcetype=syndication)  OR (index=_internal sourcetype="syndication_modular_input")

Second, see if the following tells you why entries are being skipped:

index=_internal sourcetype="syndication_modular_input" | rex field=_raw "(?<action>((Skipping)|(Including)))" | search count>0 OR action=Including  | table date latest_date title action count
0 Karma

tp92222
Explorer

Yes i am able to see some logs

but once i configure rss input it doent get displayed in Data inputs menu

please refer below screen shot

https://app.box.com/s/1sp9sp0b7hi1quxjh9aw37qora6g2hbr

i am not able to make changes to those inputs or delete rss input feeds

0 Karma

LukeMurphey
Champion

Ah, I see now. The input isn't even showing up. Check the logs in the _internal index for anything that indicates that the modular input could not be run. Also, check the messages list (in the top-right of the screen) to see if it says something about the modular input failing to initialize.

0 Karma

tp92222
Explorer

i am getting following logs

https://app.box.com/s/58kz5lifwiegnz0wopxxindwy8gnx0if

also there is no msg like "modular input failing to initialize."

0 Karma

LukeMurphey
Champion

Is this a public RSS feed? I'm struggling to reproduce this and I' m wondering if it I could reproduce it with the feed you are using it with. Let me know if you can share the feed URL with me.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...