Splunk Enterprise Security

Splunk Enterprise Security: Unable to save Input stanza for lookup source

prammod123
Explorer

We are implementing the Splunk ES in our environment, when I try to save input stanza for lookup source under Configure > Data Enrichment > Identity Management, I receive an error "Encountered the following error while trying to save: The following required arguments are missing: master_host."

Any references are much appreciated.

0 Karma

lakshman239
Influencer

Under Configure > Data Enrichment > Identity Management, are you trying to update an existing definition (i.e 'Name') or adding your own? Did you try to change/update the config from back-end ?(SA-IdentityManagement/local)

0 Karma

prammod123
Explorer

BTW, I see master_host attirbute of SA-IdentityManagement addon inputs.conf has not been set and not sure what value to set for the attribute master_host

0 Karma

prammod123
Explorer

I am trying to create a new definition

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...