<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Got this error &amp;quot;Unable to initialize modular input&amp;quot; from indexer after deploy a Splunk_TA_paloalto  to indexer in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Got-this-error-quot-Unable-to-initialize-modular-input-quot-from/m-p/313765#M166273</link>
    <description>&lt;P&gt;According to this link,&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/AddOns/released/Overview/Distributedinstall"&gt;http://docs.splunk.com/Documentation/AddOns/released/Overview/Distributedinstall&lt;/A&gt;&lt;BR /&gt;
(Indexer cluster section)&lt;/P&gt;

&lt;P&gt;We need to remove the following file if the TA is deployed to indexer cluster.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Remove the eventgen.conf files and all files in the samples folder.&lt;/LI&gt;
&lt;LI&gt;Remove the inputs.conf file, if it contains one.&lt;/LI&gt;
&lt;LI&gt;Remove the database.conf file, if it contains one.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;In your case, you can run the following command to fix the issue.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;mv /opt/splunk/etc/master-apps/Splunk_TA_paloalto/default/inputs.conf /opt/splunk/etc/master-apps/Splunk_TA_paloalto/default/inputs.conf.orig

mv /opt/splunk/etc/master-apps/Splunk_TA_paloalto/README/inputs.conf.spec /opt/splunk/etc/master-apps/Splunk_TA_paloalto/README/inputs.conf.spec.orig
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 31 Aug 2017 04:19:48 GMT</pubDate>
    <dc:creator>daniel_splunk</dc:creator>
    <dc:date>2017-08-31T04:19:48Z</dc:date>
    <item>
      <title>Got this error "Unable to initialize modular input" from indexer after deploy a Splunk_TA_paloalto  to indexer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Got-this-error-quot-Unable-to-initialize-modular-input-quot-from/m-p/313764#M166272</link>
      <description>&lt;P&gt;The error message that I got is this one. But I found that it is a general error and would like to know the root cause.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Search peer idx16.my-indexcluster.com has the following message: Unable to initialize modular input "autofocus_export" defined inside the app "Splunk_TA_paloalto": Unable to locate suitable script for introspection.

Search peer idx2.my-indexcluster.com has the following message: Unable to initialize modular input "autofocus_export" defined inside the app "Splunk_TA_paloalto": Unable to locate suitable script for introspection.

Search peer idx6.my-indexcluster.com has the following message: Unable to initialize modular input "autofocus_export" defined inside the app "Splunk_TA_paloalto": Unable to locate suitable script for introspection.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 31 Aug 2017 04:16:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Got-this-error-quot-Unable-to-initialize-modular-input-quot-from/m-p/313764#M166272</guid>
      <dc:creator>daniel_splunk</dc:creator>
      <dc:date>2017-08-31T04:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: Got this error "Unable to initialize modular input" from indexer after deploy a Splunk_TA_paloalto  to indexer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Got-this-error-quot-Unable-to-initialize-modular-input-quot-from/m-p/313765#M166273</link>
      <description>&lt;P&gt;According to this link,&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/AddOns/released/Overview/Distributedinstall"&gt;http://docs.splunk.com/Documentation/AddOns/released/Overview/Distributedinstall&lt;/A&gt;&lt;BR /&gt;
(Indexer cluster section)&lt;/P&gt;

&lt;P&gt;We need to remove the following file if the TA is deployed to indexer cluster.&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;Remove the eventgen.conf files and all files in the samples folder.&lt;/LI&gt;
&lt;LI&gt;Remove the inputs.conf file, if it contains one.&lt;/LI&gt;
&lt;LI&gt;Remove the database.conf file, if it contains one.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;In your case, you can run the following command to fix the issue.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;mv /opt/splunk/etc/master-apps/Splunk_TA_paloalto/default/inputs.conf /opt/splunk/etc/master-apps/Splunk_TA_paloalto/default/inputs.conf.orig

mv /opt/splunk/etc/master-apps/Splunk_TA_paloalto/README/inputs.conf.spec /opt/splunk/etc/master-apps/Splunk_TA_paloalto/README/inputs.conf.spec.orig
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 31 Aug 2017 04:19:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Got-this-error-quot-Unable-to-initialize-modular-input-quot-from/m-p/313765#M166273</guid>
      <dc:creator>daniel_splunk</dc:creator>
      <dc:date>2017-08-31T04:19:48Z</dc:date>
    </item>
    <item>
      <title>Re: Got this error "Unable to initialize modular input" from indexer after deploy a Splunk_TA_paloalto  to indexer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Got-this-error-quot-Unable-to-initialize-modular-input-quot-from/m-p/313766#M166274</link>
      <description>&lt;P&gt;Hi Daniel.&lt;/P&gt;

&lt;P&gt;I have this same problem and want to be clear on your solution.  &lt;/P&gt;

&lt;P&gt;I deploy this add-on from a deployment server.  It gets pushed to my search heads and indexers.&lt;/P&gt;

&lt;P&gt;Are you saying to remove the listed files on the deployment server then push out or remove on just the indexers?  If just the indexers, how do you do this while still having those files pushed to your search heads?&lt;/P&gt;

&lt;P&gt;Thanks a bunch!&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2017 18:52:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Got-this-error-quot-Unable-to-initialize-modular-input-quot-from/m-p/313766#M166274</guid>
      <dc:creator>darlas</dc:creator>
      <dc:date>2017-11-22T18:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: Got this error "Unable to initialize modular input" from indexer after deploy a Splunk_TA_paloalto  to indexer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Got-this-error-quot-Unable-to-initialize-modular-input-quot-from/m-p/313767#M166275</link>
      <description>&lt;P&gt;Does your indexer in a cluster environment? That procedure only apply to indexer cluster. That means you need to change Splunk_TA_paloalto in cluster master and then deploy to indexer member.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:52:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Got-this-error-quot-Unable-to-initialize-modular-input-quot-from/m-p/313767#M166275</guid>
      <dc:creator>daniel_splunk</dc:creator>
      <dc:date>2020-09-29T16:52:33Z</dc:date>
    </item>
    <item>
      <title>Re: Got this error "Unable to initialize modular input" from indexer after deploy a Splunk_TA_paloalto  to indexer</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Got-this-error-quot-Unable-to-initialize-modular-input-quot-from/m-p/313768#M166276</link>
      <description>&lt;P&gt;Hi Daniel.&lt;/P&gt;

&lt;P&gt;Thanks for the quick response.  We have multiple indexers but do not believe they are in a cluster.  There is no "master" indexer.  we do have a Deployment Server that manages all indexers, search heads, etc...  But I don't think that is what you mean.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2017 16:50:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Got-this-error-quot-Unable-to-initialize-modular-input-quot-from/m-p/313768#M166276</guid>
      <dc:creator>darlas</dc:creator>
      <dc:date>2017-11-27T16:50:16Z</dc:date>
    </item>
  </channel>
</rss>

