The Splunk app AbuseIPdb_check (https://splunkbase.splunk.com/app/4903) is not working as expected after copying the config.json file to this app's local directory and putting my AbuseIPDB API key.
I have tried with syntax as below - | makeresults | eval ip="184.108.40.206" | abuseip ipfield=ip | makeresults | eval ip="220.127.116.11" |abuseip(ip)
The error on Splunk web is -- Error in 'script': Get info probe failed for external search command 'abuseip'.
i did not find anything relevant as a pointer when checked in Splunk _internal logs for this.
Under all configuration "abuseip" is mentioned as config type - command with enabled status and global sharing permissions.
Has it worked for anyone? any direction/solution pointer would be appreciable.
I am having the same issue. Can't seem to find a solution for this one yet.
I'm having similar issues, however strangely enough there are a few times where the script actually works.
Here is the command that worked (works randomly) for me:
syntax = | abuseip ipfield=<insert field name>
example = | abuseip ipfield=destip
As far as the error goes, I was able to find these two sources but non of them helped. Might help you out.