<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Commands not usable from Enterprise Security? in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Commands-not-usable-from-Enterprise-Security/m-p/354616#M3397</link>
    <description>&lt;P&gt;Yeah, ES is a special kind of app. You'll need to check that link jkat54 mentioned.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Mar 2017 14:24:13 GMT</pubDate>
    <dc:creator>muebel</dc:creator>
    <dc:date>2017-03-14T14:24:13Z</dc:date>
    <item>
      <title>Commands not usable from Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Commands-not-usable-from-Enterprise-Security/m-p/354611#M3392</link>
      <description>&lt;P&gt;I have an app installed from Splunkbase, which has custom search command defined in it. I've set the commands to be globally available, and it works fine. I can invoke the commands from any of the apps I have in Splunk, except Enterprise Security.&lt;/P&gt;

&lt;P&gt;Is there a way to configure ES to be able to invoke commands from other app's context?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 13:32:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Commands-not-usable-from-Enterprise-Security/m-p/354611#M3392</guid>
      <dc:creator>szabados</dc:creator>
      <dc:date>2017-03-14T13:32:53Z</dc:date>
    </item>
    <item>
      <title>Re: Commands not usable from Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Commands-not-usable-from-Enterprise-Security/m-p/354612#M3393</link>
      <description>&lt;P&gt;Check the default.meta and local.meta in the ess app/metadata folder to see if there is an IMPORT key.&lt;/P&gt;

&lt;P&gt;If so, add your app to that key&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 13:39:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Commands-not-usable-from-Enterprise-Security/m-p/354612#M3393</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-03-14T13:39:28Z</dc:date>
    </item>
    <item>
      <title>Re: Commands not usable from Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Commands-not-usable-from-Enterprise-Security/m-p/354613#M3394</link>
      <description>&lt;P&gt;Hi szabados, ES uses a modular input to control what is allowed in the app context. This input is called &lt;CODE&gt;app_imports_update&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;The input has a few config directives, &lt;CODE&gt;app_regex&lt;/CODE&gt; in particular controls what comes in. You'll have to update this regex to include the pattern that matches the name of the app you want in.&lt;/P&gt;

&lt;P&gt;More info available here:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/ES/4.6.0/Install/InstallTechnologyAdd-ons"&gt;http://docs.splunk.com/Documentation/ES/4.6.0/Install/InstallTechnologyAdd-ons&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Please let me know if this answers your question! &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 13:46:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Commands-not-usable-from-Enterprise-Security/m-p/354613#M3394</guid>
      <dc:creator>muebel</dc:creator>
      <dc:date>2017-03-14T13:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: Commands not usable from Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Commands-not-usable-from-Enterprise-Security/m-p/354614#M3395</link>
      <description>&lt;P&gt;Thanks, this has been a headache for me for a while &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 13:52:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Commands-not-usable-from-Enterprise-Security/m-p/354614#M3395</guid>
      <dc:creator>szabados</dc:creator>
      <dc:date>2017-03-14T13:52:58Z</dc:date>
    </item>
    <item>
      <title>Re: Commands not usable from Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Commands-not-usable-from-Enterprise-Security/m-p/354615#M3396</link>
      <description>&lt;P&gt;As per muebel's comment below, ES may revert this change when it runs it's configuration checkers.  Sounds like you need to do what he is suggesting by editing the modular input called app_imports_update.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/ES/4.6.0/Install/InstallTechnologyAdd-ons#Import_custom_apps_and_add-ons" target="_blank"&gt;http://docs.splunk.com/Documentation/ES/4.6.0/Install/InstallTechnologyAdd-ons#Import_custom_apps_and_add-ons&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:13:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Commands-not-usable-from-Enterprise-Security/m-p/354615#M3396</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2020-09-29T13:13:19Z</dc:date>
    </item>
    <item>
      <title>Re: Commands not usable from Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Commands-not-usable-from-Enterprise-Security/m-p/354616#M3397</link>
      <description>&lt;P&gt;Yeah, ES is a special kind of app. You'll need to check that link jkat54 mentioned.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2017 14:24:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Commands-not-usable-from-Enterprise-Security/m-p/354616#M3397</guid>
      <dc:creator>muebel</dc:creator>
      <dc:date>2017-03-14T14:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Commands not usable from Enterprise Security?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Commands-not-usable-from-Enterprise-Security/m-p/354617#M3398</link>
      <description>&lt;P&gt;In ES you can go to "Configure&amp;gt;General&amp;gt;App Imports Update". From there just change the settings for update_es: &lt;/P&gt;

&lt;P&gt;update_es   (SA-.&lt;EM&gt;)|(Splunk_SA_.&lt;/EM&gt;)  (appsbrowser)|(search)|([ST]A-.&lt;EM&gt;)|(Splunk_[ST]A_.&lt;/EM&gt;)|(DA-ESS-.&lt;EM&gt;)|(Splunk_DA-ESS_.&lt;/EM&gt;)|(slack_alerts)&lt;/P&gt;

&lt;P&gt;In my case I just added |(slack_alerts) to the regex which will import the app slack_alerts from Splunkbase.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:13:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Commands-not-usable-from-Enterprise-Security/m-p/354617#M3398</guid>
      <dc:creator>kchamplin_splun</dc:creator>
      <dc:date>2020-09-29T13:13:52Z</dc:date>
    </item>
  </channel>
</rss>

