<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: splunk rejects geo macro in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/splunk-rejects-geo-macro/m-p/78088#M1109</link>
    <description>&lt;P&gt;this problem went away when I upgraded to splunk 4.2.3&lt;/P&gt;</description>
    <pubDate>Mon, 19 Sep 2011 19:39:32 GMT</pubDate>
    <dc:creator>natestelladot</dc:creator>
    <dc:date>2011-09-19T19:39:32Z</dc:date>
    <item>
      <title>splunk rejects geo macro</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/splunk-rejects-geo-macro/m-p/78087#M1108</link>
      <description>&lt;P&gt;I have the google maps application for splunk and configured geo location on it, and it works fine (search | geoip ip_address returns stuff). However when I try to configure web analytics with this app splunk rejects the data input.&lt;/P&gt;

&lt;P&gt;What I think I should put in is&lt;/P&gt;

&lt;P&gt;| geoip ip_address&lt;/P&gt;

&lt;P&gt;but no matter what variation I try (quotes, no quotes etc) Splunk always barfs. Sample error from log&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;09-19-2011 19:10:34.896 +0000 ERROR AdminManager - Unexpected error "&amp;lt;class 'splunk.BadRequest'&amp;gt;" from python handler: "[HTTP 400] Bad Request; [{'text': 'In handler \'macros\': Argument "disabled" is not supported by this handler.', 'code': None, 'type': 'ERROR'}]".  See splunkd.log for more details.
09-19-2011 19:13:58.251 +0000 ERROR AdminManager - Stack trace from python handler:
Traceback (most recent call last):
  File "/opt/splunk/lib/python2.6/site-packages/splunk/admin.py", line 60, in init
    hand.execute(info)
  File "/opt/splunk/lib/python2.6/site-packages/splunk/admin.py", line 433, in execute
    if self.requestedAction == ACTION_EDIT:     self.handleEdit(confInfo)
  File "/opt/splunk/etc/apps/web_analytics/bin/sideview_wa_setup_handler.py", line 66, in handleEdit
    en.setEntity(macro,sessionKey=sessionKey)
  File "/opt/splunk/lib/python2.6/site-packages/splunk/entity.py", line 308, in setEntity
    serverResponse, serverContent = rest.simpleRequest(uri, sessionKey=sessionKey, postargs=postargs, raiseAllErrors=True)
  File "/opt/splunk/lib/python2.6/site-packages/splunk/rest/__init__.py", line 468, in simpleRequest
    raise splunk.BadRequest, (None, serverResponse.messages)
BadRequest: [HTTP 400] Bad Request; [{'text': 'In handler \'macros\': Argument "disabled" is not supported by this handler.', 'code': None, 'type': 'ERROR'}]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The configuration screen mentions pasting one of the quote characters incorrectly, however I see no quote characters.&lt;/P&gt;

&lt;P&gt;Running Splunk 4.2.1, and I downloaded this web analytics application last week.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2011 19:20:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/splunk-rejects-geo-macro/m-p/78087#M1108</guid>
      <dc:creator>natestelladot</dc:creator>
      <dc:date>2011-09-19T19:20:30Z</dc:date>
    </item>
    <item>
      <title>Re: splunk rejects geo macro</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/splunk-rejects-geo-macro/m-p/78088#M1109</link>
      <description>&lt;P&gt;this problem went away when I upgraded to splunk 4.2.3&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2011 19:39:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/splunk-rejects-geo-macro/m-p/78088#M1109</guid>
      <dc:creator>natestelladot</dc:creator>
      <dc:date>2011-09-19T19:39:32Z</dc:date>
    </item>
  </channel>
</rss>

