Splunk Enterprise Security

Issue with Identity Management lookup expansion with ESS v 3.0 and Splunk 6.0.1 on Windows Platforms

dshakespeare_sp
Splunk Employee
Splunk Employee

Customers running Splunk ESS 3.0 / Splunk 6.0.1 on Windows platforms may experience issues with lookup expansions/creation not working correctly in Identity Management.

There may also be further problems with the Asset/Identity Investigators dashboard eg Asset/identity information is displayed in the upper part of the screen, but the swim lanes at the bottom just show a constant stream of progress dots which never complete.

1 Solution

dshakespeare_sp
Splunk Employee
Splunk Employee

There are known issues with the Windows version of ESS 3.0 with Splunk 6.0.1 (SOLNESS-4642)
These issues are resolved with a new version of "writers.py" and upgrading Splunk to version 6.0.2

If you are experiencing issues Identity Management expansion on Windows and require the new "writers.py"please raise a support ticket with Splunk support quoting this Splunk Answer.

The new file will be included in Splunk For Enterprise Security 3.0.1 and "upgrade" safe

View solution in original post

dshakespeare_sp
Splunk Employee
Splunk Employee

There are known issues with the Windows version of ESS 3.0 with Splunk 6.0.1 (SOLNESS-4642)
These issues are resolved with a new version of "writers.py" and upgrading Splunk to version 6.0.2

If you are experiencing issues Identity Management expansion on Windows and require the new "writers.py"please raise a support ticket with Splunk support quoting this Splunk Answer.

The new file will be included in Splunk For Enterprise Security 3.0.1 and "upgrade" safe

Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...