All Apps and Add-ons

After installing the Splunk_TA_oracle, my splunk instance stopped collecting logs

yannK
Splunk Employee
Splunk Employee

Just after installing the Splunk_TA_oracle, I noticed that my splunk instance stopped collecting logs :
- no more files monitored
- no summary indexing

And from a btool and the manager I saw that all "monitor" and "batch" were disabled.
Because of the setting in etc/apps/Splunk_TA_oracle/default/inputs.conf

[default]
disabled = 1

This setting applied to all the other inputs on the other apps. and cannot be removed from the UI

1 Solution

yannK
Splunk Employee
Splunk Employee

The workaround was

  • remove the app
  • or enable the defaults adding in $SPLUNK_HOME/etc/apps/Splunk_TA_oracle/local/inputs.conf

    [default]
    disabled = 0

View solution in original post

yannK
Splunk Employee
Splunk Employee

The workaround was

  • remove the app
  • or enable the defaults adding in $SPLUNK_HOME/etc/apps/Splunk_TA_oracle/local/inputs.conf

    [default]
    disabled = 0

jcoates_splunk
Splunk Employee
Splunk Employee

Version 3.1.2 solves this problem. We've also updated our best practices training.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...