<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Enterprise Security Message in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-Message/m-p/154187#M611</link>
    <description>&lt;P&gt;This error is occurring because Enterprise Security contains a "configuration_checker.py" modular input that attempts to alert you when misconfigurations are detected - we attempt to be proactive and alert to conditions that might be causing the application to misbehave.&lt;/P&gt;

&lt;P&gt;In this case, the intent of the alert is to alert when a scripted input or modular input has exited abnormally. The definition of "abnormally" that we use means "exited with a non-zero exit code".&lt;/P&gt;

&lt;P&gt;Sometimes, as in this case, this particular check backfires. The error you're seeing is benign and is occurring because the scripted inputs included with the TA-windows add-on use  non-zero exit codes even when they exit successfully. This has been corrected in an upcoming version (which of course doesn't help in this instance).&lt;/P&gt;

&lt;P&gt;If you would like to just get rid of the message, you can disable this input stanza in the Manager:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Settings --&amp;gt; Data Inputs --&amp;gt; Configuration Checker --&amp;gt; confcheck_script_errors
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, that would disable the exit status checking for ALL scripted and modular inputs on the system. If you'd like a more robust solution, reach out to support and mention this posting, and we can provide a small patch to the configuration_checker.py script which will deal with this in a more intelligent fashion - with the caveat that it wouldn't persist beyond an upgrade.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2014 03:11:21 GMT</pubDate>
    <dc:creator>jervin_splunk</dc:creator>
    <dc:date>2014-02-21T03:11:21Z</dc:date>
    <item>
      <title>Enterprise Security Message</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-Message/m-p/154186#M610</link>
      <description>&lt;P&gt;msg="A script exited abnormally" input="C:\Program Files\Splunk\bin\splunk-winprintmon.exe" stanza="default" status="exited with code -1"&lt;/P&gt;

&lt;P&gt;I keep getting this message, any help would be great!&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2014 00:09:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-Message/m-p/154186#M610</guid>
      <dc:creator>careoregon</dc:creator>
      <dc:date>2014-02-18T00:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security Message</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-Message/m-p/154187#M611</link>
      <description>&lt;P&gt;This error is occurring because Enterprise Security contains a "configuration_checker.py" modular input that attempts to alert you when misconfigurations are detected - we attempt to be proactive and alert to conditions that might be causing the application to misbehave.&lt;/P&gt;

&lt;P&gt;In this case, the intent of the alert is to alert when a scripted input or modular input has exited abnormally. The definition of "abnormally" that we use means "exited with a non-zero exit code".&lt;/P&gt;

&lt;P&gt;Sometimes, as in this case, this particular check backfires. The error you're seeing is benign and is occurring because the scripted inputs included with the TA-windows add-on use  non-zero exit codes even when they exit successfully. This has been corrected in an upcoming version (which of course doesn't help in this instance).&lt;/P&gt;

&lt;P&gt;If you would like to just get rid of the message, you can disable this input stanza in the Manager:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Settings --&amp;gt; Data Inputs --&amp;gt; Configuration Checker --&amp;gt; confcheck_script_errors
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;However, that would disable the exit status checking for ALL scripted and modular inputs on the system. If you'd like a more robust solution, reach out to support and mention this posting, and we can provide a small patch to the configuration_checker.py script which will deal with this in a more intelligent fashion - with the caveat that it wouldn't persist beyond an upgrade.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2014 03:11:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-Message/m-p/154187#M611</guid>
      <dc:creator>jervin_splunk</dc:creator>
      <dc:date>2014-02-21T03:11:21Z</dc:date>
    </item>
    <item>
      <title>Re: Enterprise Security Message</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-Message/m-p/154188#M612</link>
      <description>&lt;P&gt;We are having this issue as well. Thanks for to clear answer to this problem. We will get a case open with support about it.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Feb 2014 16:08:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Enterprise-Security-Message/m-p/154188#M612</guid>
      <dc:creator>delink</dc:creator>
      <dc:date>2014-02-26T16:08:59Z</dc:date>
    </item>
  </channel>
</rss>

