<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with App to get approved over Splunk Cloud in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/544733#M9764</link>
    <description>&lt;P&gt;Hi Rich,&lt;/P&gt;&lt;P&gt;Please find the below line,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[syslog]&lt;BR /&gt;TIME_PREFIX = (?:^.*Centrify.*whenoccurreddate=|^.*?)&lt;BR /&gt;TRANSFORMS-centrify_cisp_syslog_transforms = centrify_cisp_syslog_regex&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And transform.conf file below,&lt;/P&gt;&lt;P&gt;[centrify_cisp_headers]&lt;BR /&gt;REGEX = .*\d{1,2}\:\d{1,2}\:\d{1,2}\.*?\s(?&amp;lt;system&amp;gt;[^\s]*)\s+.*INFO\s+(?&amp;lt;product&amp;gt;(?:[^|\\]|(?:\\{2})|\\\|)+)\|(?&amp;lt;category&amp;gt;(?:[^|\\]|(?:\\{2})|\\\|)+)\|(?&amp;lt;eventname&amp;gt;(?:[^|\\]|(?:\\{2})|\\\|)+)&lt;/P&gt;&lt;P&gt;[centrify_cisp_syslog_regex]&lt;BR /&gt;REGEX = .*Centrify.*whenoccurreddate=.*&lt;BR /&gt;FORMAT = sourcetype::centrify_cisp_syslog&lt;BR /&gt;DEST_KEY = MetaData:Sourcetype&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 22 Mar 2021 07:02:57 GMT</pubDate>
    <dc:creator>PratikPashte</dc:creator>
    <dc:date>2021-03-22T07:02:57Z</dc:date>
    <item>
      <title>Help with App to get approved over Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/544461#M9762</link>
      <description>&lt;P&gt;I have vendor whose application is yet not supported on Splunk Cloud but can be installed on HF.&lt;/P&gt;&lt;P&gt;I thought to check what error I am getting post uploading the app, so if possible I can tweak and can get that approved.&lt;/P&gt;&lt;P&gt;Post uploading I got the below failure summary, I need help to understand the error and if possible to get that resolve&lt;/P&gt;&lt;P&gt;I had followed below dev guide as well but not able to get the proper understanding which can help to resolve the error.&amp;nbsp;&lt;/P&gt;&lt;P&gt;[ Failure Summary ]&lt;BR /&gt;Failures will block the Cloud Vetting. They must be fixed.&lt;BR /&gt;check_pretrained_sourcetypes_have_only_allowed_transforms&lt;BR /&gt;Only TRANSFORMS- or SEDCMD options are allowed for pretrained sourcetypes. File: default/props.conf Line Number: 3&lt;/P&gt;&lt;P&gt;Dev Guide:&amp;nbsp;&lt;A href="https://dev.splunk.com/enterprise/docs/reference/splunkappinspectcheck/" target="_blank" rel="noopener"&gt;https://dev.splunk.com/enterprise/docs/reference/splunkappinspectcheck/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 09:14:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/544461#M9762</guid>
      <dc:creator>PratikPashte</dc:creator>
      <dc:date>2021-03-19T09:14:11Z</dc:date>
    </item>
    <item>
      <title>Re: Help with App to get approved over Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/544491#M9763</link>
      <description>&lt;P&gt;Please share lines #1-3 from the app's props.conf file.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Mar 2021 12:15:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/544491#M9763</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-03-19T12:15:23Z</dc:date>
    </item>
    <item>
      <title>Re: Help with App to get approved over Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/544733#M9764</link>
      <description>&lt;P&gt;Hi Rich,&lt;/P&gt;&lt;P&gt;Please find the below line,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;[syslog]&lt;BR /&gt;TIME_PREFIX = (?:^.*Centrify.*whenoccurreddate=|^.*?)&lt;BR /&gt;TRANSFORMS-centrify_cisp_syslog_transforms = centrify_cisp_syslog_regex&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And transform.conf file below,&lt;/P&gt;&lt;P&gt;[centrify_cisp_headers]&lt;BR /&gt;REGEX = .*\d{1,2}\:\d{1,2}\:\d{1,2}\.*?\s(?&amp;lt;system&amp;gt;[^\s]*)\s+.*INFO\s+(?&amp;lt;product&amp;gt;(?:[^|\\]|(?:\\{2})|\\\|)+)\|(?&amp;lt;category&amp;gt;(?:[^|\\]|(?:\\{2})|\\\|)+)\|(?&amp;lt;eventname&amp;gt;(?:[^|\\]|(?:\\{2})|\\\|)+)&lt;/P&gt;&lt;P&gt;[centrify_cisp_syslog_regex]&lt;BR /&gt;REGEX = .*Centrify.*whenoccurreddate=.*&lt;BR /&gt;FORMAT = sourcetype::centrify_cisp_syslog&lt;BR /&gt;DEST_KEY = MetaData:Sourcetype&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 07:02:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/544733#M9764</guid>
      <dc:creator>PratikPashte</dc:creator>
      <dc:date>2021-03-22T07:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: Help with App to get approved over Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/544759#M9765</link>
      <description>&lt;P&gt;Per the error message "&lt;SPAN&gt;Only TRANSFORMS- or SEDCMD options are allowed for pretrained sourcetypes", but you have TIME_PREFIX.&amp;nbsp; Either get rid of TIME_PREFIX or use a custom sourcetype.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 12:27:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/544759#M9765</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-03-22T12:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: Help with App to get approved over Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/544771#M9766</link>
      <description>&lt;P&gt;Hi Rich,&lt;/P&gt;&lt;P&gt;I can remove time prefix but would not get "when occurred" date field which would be needed.&lt;/P&gt;&lt;P&gt;When you say custom source type meaning a separate stanza in props.conf and associated regex under transofrms.conf file right?&lt;/P&gt;&lt;P&gt;Like props would look like this,&lt;/P&gt;&lt;P&gt;[cp_centrify_syslog]&lt;BR /&gt;TRANSFORMS-cp_centrify_cisp_syslog_transforms = cp_centrify_cisp_syslog_regex&lt;/P&gt;&lt;P&gt;[syslog]&lt;BR /&gt;TRANSFORMS-centrify_cisp_syslog_transforms = centrify_cisp_syslog_regex&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And transform would look like this,&lt;/P&gt;&lt;P&gt;[cp_centrify_cisp_syslog_regex]&lt;BR /&gt;REGEX = (?:^.*Centrify.*whenoccurreddate=|^.*?)&lt;BR /&gt;FORMAT = sourcetype::centrify_cisp_syslog&lt;/P&gt;&lt;P&gt;[centrify_cisp_syslog_regex]&lt;BR /&gt;REGEX = .*Centrify.*whenoccurreddate=.*&lt;BR /&gt;FORMAT = sourcetype::centrify_cisp_syslog&lt;BR /&gt;DEST_KEY = MetaData:Sourcetype&lt;/P&gt;&lt;P&gt;&amp;nbsp;Does this needs to be done?&lt;/P&gt;&lt;P&gt;Thank you for your help.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 13:20:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/544771#M9766</guid>
      <dc:creator>PratikPashte</dc:creator>
      <dc:date>2021-03-22T13:20:02Z</dc:date>
    </item>
    <item>
      <title>Re: Help with App to get approved over Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/544785#M9767</link>
      <description>&lt;P&gt;By "custom sourcetype" I was thinking of something a little simpler.&lt;/P&gt;&lt;P&gt;In props.conf replace &lt;FONT face="courier new,courier"&gt;[syslog]&lt;/FONT&gt; with &lt;FONT face="courier new,courier"&gt;[centrify_syslog]&lt;/FONT&gt; then have all syslog data from Centrify specify the new sourcetype.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 14:39:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/544785#M9767</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-03-22T14:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: Help with App to get approved over Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/544889#M9768</link>
      <description>&lt;P&gt;I guess this worked only thing now I need to figure out is below,&lt;/P&gt;&lt;P&gt;I cannot do this,&amp;nbsp;&lt;/P&gt;&lt;P&gt;$SPLUNK_HOME/bin/splunk package app &amp;lt;APP_NAME&amp;gt;&lt;/P&gt;&lt;P&gt;As I am having Splunk Cloud don't have access to the box not sure whether can be done on deployment server, also as&amp;nbsp;Splunk recommends 644 for all files outside of bin/ and 755 for all directories and files in the bin/ directory that is already in place but not sure whether windows is still messing with permission...&lt;/P&gt;&lt;P&gt;[ Failure Summary ]&lt;BR /&gt;Failures will block the Cloud Vetting. They must be fixed.&lt;BR /&gt;check_for_bin_files&lt;BR /&gt;This file has execute permissions for owners, groups, or others. File: test&lt;BR /&gt;This file has execute permissions for owners, groups, or others. File: license-eula.txt&lt;BR /&gt;This file has execute permissions for owners, groups, or others. File: README.md&lt;BR /&gt;This file has execute permissions for owners, groups, or others. File: default/inputs.conf.example&lt;BR /&gt;This file has execute permissions for owners, groups, or others. File: default/app.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 08:44:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/544889#M9768</guid>
      <dc:creator>PratikPashte</dc:creator>
      <dc:date>2021-03-23T08:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: Help with App to get approved over Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/544915#M9769</link>
      <description>&lt;P&gt;Yes, you should be able to package the app on the DS.&amp;nbsp; Packaging on a Windows box, however, will cause the app to fail AppInspect because of the permissions settings.&amp;nbsp; If you package on Windows, you'll need to transfer the package to a Linux machine, extract the files, change permissions, then re-tar the package.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 12:22:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/544915#M9769</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-03-23T12:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: Help with App to get approved over Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/545269#M9770</link>
      <description>&lt;P&gt;I did that taking package at Linux extracting doing changes and repackaging.&lt;/P&gt;&lt;P&gt;But still getting same error although the permissions are as per requirement.&lt;/P&gt;&lt;P&gt;I will be now trying to utilize splunk app package utility, to do so, would just need validation on steps to follow,&lt;/P&gt;&lt;P&gt;Place the app (.tgz file or extracted package?) under&amp;nbsp;&lt;STRONG&gt;$SPLUNK_HOME/etc/apps,&amp;nbsp;&lt;/STRONG&gt;then to go under,&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;$SPLUNK_HOME/bin/&amp;nbsp;&lt;/STRONG&gt;and to run below command right?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;splunk package app &amp;lt;APP_NAME&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;and the app&amp;nbsp;&lt;SPAN&gt;will output to&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;$SPLUNK_HOME/etc/system/static/app-packages&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Thank you in advanced&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 06:41:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/545269#M9770</guid>
      <dc:creator>PratikPashte</dc:creator>
      <dc:date>2021-03-25T06:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: Help with App to get approved over Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/545379#M9771</link>
      <description>&lt;P&gt;Yes, those are the steps.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 12:59:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/545379#M9771</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-03-25T12:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: Help with App to get approved over Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/545382#M9772</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for all your help.&lt;/P&gt;&lt;P&gt;I had actually changed the files permission for the one which got with the report to 644 and it worked.&lt;/P&gt;&lt;P&gt;Rather changing the directory permission recursively i changed only required file permission.&lt;/P&gt;&lt;P&gt;Do not need to use that tool but I guess in future splunk package app would make sense to use rather changing each file permission to get this worked.&lt;/P&gt;&lt;P&gt;Last question..&lt;/P&gt;&lt;P&gt;Now as I added custom sourctype to props.conf file replacing syslog and I would be taking that data from syslog server.&lt;/P&gt;&lt;P&gt;So I should add that sourcetype at syslog server side and same I will get as I am going to install that app on Splunk cloud right?&lt;/P&gt;&lt;P&gt;If possible you can provide some information about the workflow from app custom sourcetype to splunk cloud would be great help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 13:06:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/545382#M9772</guid>
      <dc:creator>PratikPashte</dc:creator>
      <dc:date>2021-03-25T13:06:25Z</dc:date>
    </item>
    <item>
      <title>Re: Help with App to get approved over Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/545438#M9773</link>
      <description>&lt;P&gt;Yes, the custom sourcetype must be referenced on the syslog server so Splunk knows to apply that sourcetype to the data.&lt;/P&gt;&lt;P&gt;Submit your custom to Splunk Cloud by going to the App Management page in your SC instance.&amp;nbsp; Then select the Uploaded Apps tab and click the Upload App button.&amp;nbsp; Provide your splunk.com credentials (those you use for splunkbase) and choose the file to upload.&amp;nbsp; Splunk will automatically run AppInspect and let you know the results.&amp;nbsp; If the app passes AppInspect then there will be a link you can click to install the app; otherwise, review the results to see why the app failed.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 15:56:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Help-with-App-to-get-approved-over-Splunk-Cloud/m-p/545438#M9773</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-03-25T15:56:50Z</dc:date>
    </item>
  </channel>
</rss>

