<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Uploading Private App in Splunk Cloud in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Uploading-Private-App-in-Splunk-Cloud/m-p/530207#M89267</link>
    <description>&lt;P&gt;Did you try again as the message suggested?&amp;nbsp; If so, what were those results?&amp;nbsp; Did you or your admin look in the _internal index to see if there are any details (I'm not sure if there would be any, but it's worth looking)?&lt;/P&gt;&lt;P&gt;BTW, *masking* data does not save license.&amp;nbsp; Masking just replaces some characters with others so the original content is hidden.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, app names beginning with "splunk" should be used only by Splunk itself.&amp;nbsp; Perhaps this is why vetting failed.&amp;nbsp; Your names should start with the name of your company.&amp;nbsp; This will make it easier to identify the source of the app in the future and avoid confusion when your replacement tries to find "Splunk_TA_Wineventlog_Props" on splunkbase.&lt;/P&gt;</description>
    <pubDate>Fri, 20 Nov 2020 13:48:32 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2020-11-20T13:48:32Z</dc:date>
    <item>
      <title>Uploading Private App in Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Uploading-Private-App-in-Splunk-Cloud/m-p/530177#M89264</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;My goal is to mask the Wineventlog:Security &lt;SPAN&gt;&amp;nbsp;which will be saving us from unnecessary license usage. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If we go through the below link under Saving License section it will provide more information on how to mask those details:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://hurricanelabs.com/splunk-tutorials/leveraging-windows-event-log-filtering-and-design-techniques-in-splunk/" target="_blank"&gt;https://hurricanelabs.com/splunk-tutorials/leveraging-windows-event-log-filtering-and-design-techniques-in-splunk/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So initially I have created the Private App as per the document provided below:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.1.2008/User/PrivateApps" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.1.2008/User/PrivateApps&lt;/A&gt;&lt;/P&gt;&lt;P&gt;i.e Have created a folder as &lt;EM&gt;&lt;STRONG&gt;"Splunk_TA_Wineventlog_Props"&lt;/STRONG&gt;&lt;/EM&gt; and inside that folder I have created the &lt;EM&gt;&lt;STRONG&gt;default&lt;/STRONG&gt; &lt;/EM&gt;directory and &lt;EM&gt;&lt;STRONG&gt;metadata&lt;/STRONG&gt; &lt;/EM&gt;directory.&lt;/P&gt;&lt;P&gt;In the default directory I have created the &lt;EM&gt;&lt;STRONG&gt;app.conf&lt;/STRONG&gt;&lt;/EM&gt;,&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;props.conf&lt;/STRONG&gt; &lt;/EM&gt;and &lt;EM&gt;&lt;STRONG&gt;transforms.conf&lt;/STRONG&gt; &lt;/EM&gt;as mentioned below in the link.&lt;/P&gt;&lt;P&gt;&lt;A href="https://hurricanelabs.com/splunk-tutorials/leveraging-windows-event-log-filtering-and-design-techniques-in-splunk/" target="_blank"&gt;https://hurricanelabs.com/splunk-tutorials/leveraging-windows-event-log-filtering-and-design-techniques-in-splunk/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And in &lt;EM&gt;&lt;STRONG&gt;metadata&lt;/STRONG&gt; &lt;/EM&gt;folder&amp;nbsp; I have created the &lt;EM&gt;&lt;STRONG&gt;default.meta &lt;/STRONG&gt;&lt;/EM&gt;as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then when I have zipped the &lt;EM&gt;&lt;STRONG&gt;"&lt;/STRONG&gt;&lt;STRONG&gt;Splunk_TA_Wineventlog_Props"&amp;nbsp; &lt;/STRONG&gt;&lt;/EM&gt;and then later converted from&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;zip to tgz.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Post which when i tried to upload the Created App in&lt;EM&gt;&lt;STRONG&gt; Splunk Cloud &lt;/STRONG&gt;&lt;/EM&gt;and after &lt;EM&gt;&lt;STRONG&gt;vetting &lt;/STRONG&gt;&lt;/EM&gt;process i am getting an error as &lt;EM&gt;&lt;STRONG&gt;"App validation failed to complete".&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;Unknown failure:&amp;nbsp; Contact your administrator for&amp;nbsp; details or try again later.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So kindly let me know where i am missing since as per prerequisite&amp;nbsp;i have created the app and uploaded. But don't know why it is getting an error message during vetting process.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 09:27:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Uploading-Private-App-in-Splunk-Cloud/m-p/530177#M89264</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2020-11-20T09:27:25Z</dc:date>
    </item>
    <item>
      <title>Re: Uploading Private App in Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Uploading-Private-App-in-Splunk-Cloud/m-p/530207#M89267</link>
      <description>&lt;P&gt;Did you try again as the message suggested?&amp;nbsp; If so, what were those results?&amp;nbsp; Did you or your admin look in the _internal index to see if there are any details (I'm not sure if there would be any, but it's worth looking)?&lt;/P&gt;&lt;P&gt;BTW, *masking* data does not save license.&amp;nbsp; Masking just replaces some characters with others so the original content is hidden.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, app names beginning with "splunk" should be used only by Splunk itself.&amp;nbsp; Perhaps this is why vetting failed.&amp;nbsp; Your names should start with the name of your company.&amp;nbsp; This will make it easier to identify the source of the app in the future and avoid confusion when your replacement tries to find "Splunk_TA_Wineventlog_Props" on splunkbase.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 13:48:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Uploading-Private-App-in-Splunk-Cloud/m-p/530207#M89267</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-20T13:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Uploading Private App in Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Uploading-Private-App-in-Splunk-Cloud/m-p/530216#M89269</link>
      <description>&lt;P&gt;Thank you for your swift response.&lt;/P&gt;&lt;P&gt;As per hurricane lab suggestion in the below link we are going to stop the ingestion during the index time itself&amp;nbsp; if the below keywords are present in the event.&lt;/P&gt;&lt;P&gt;This event is generated&lt;/P&gt;&lt;P&gt;Certificate information is only provided&lt;/P&gt;&lt;P&gt;Token Elevation Type indicates the type&lt;/P&gt;&lt;P&gt;&lt;A href="https://hurricanelabs.com/splunk-tutorials/leveraging-windows-event-log-filtering-and-design-techniques-in-splunk/" target="_blank" rel="noopener"&gt;https://hurricanelabs.com/splunk-tutorials/leveraging-windows-event-log-filtering-and-design-techniques-in-splunk/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can check the Saving License Topic in the link mentioned.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And also as per your advise I have changed the naming convention of the app starting with my organization name and uploaded the app in Splunk Cloud but still we are getting an error as below.&lt;/P&gt;&lt;P&gt;App Validation Failed - More Info&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Unknown failure: Contact your administrator for details or try again later.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;And there is no information about the error as well. Hence I am struck up over here.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 14:33:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Uploading-Private-App-in-Splunk-Cloud/m-p/530216#M89269</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2020-11-20T14:33:20Z</dc:date>
    </item>
    <item>
      <title>Re: Uploading Private App in Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Uploading-Private-App-in-Splunk-Cloud/m-p/530226#M89270</link>
      <description>&lt;P&gt;Consider downloading the appInspect utility so you can vet your app locally before uploading it to Splunk Cloud.&amp;nbsp; That should give you better diagnostics than what you're getting now.&amp;nbsp; See&amp;nbsp;&lt;A href="https://dev.splunk.com/enterprise/downloads" target="_blank"&gt;https://dev.splunk.com/enterprise/downloads&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Also consider opening a support request with Splunk Cloud so they can look into why your app validation is failing.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 15:14:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Uploading-Private-App-in-Splunk-Cloud/m-p/530226#M89270</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-20T15:14:55Z</dc:date>
    </item>
  </channel>
</rss>

