All Apps and Add-ons

Can't configure TA-symantec_atp v1.5.0

florin
Observer

Hi, 
I'm trying to configure TA-symantec_atp v1.5.0 on Splunk 8.1.6 version of splunk but nothing happens when I try to save the config in UI page. 


I found below errors in "/opt/splunk/var/log/splunk/python.log":

2021-09-22 13:18:41,150 +0200 ERROR __init__:164 - The REST handler module "email_symantec_util" could not be found. Python files must be in $SPLUNK_HOME/etc/apps/$MY_APP/bin/
2021-09-22 13:18:41,150 ERROR The REST handler module "email_symantec_util" could not be found. Python files must be in $SPLUNK_HOME/etc/apps/$MY_APP/bin/
2021-09-22 13:18:41,151 +0200 ERROR __init__:165 - No module named 'rapid_diag'
Traceback (most recent call last):
File "/opt/splunk/lib/python3.7/site-packages/splunk/rest/__init__.py", line 161, in dispatch
module = __import__('splunk.rest.external.%s' % parts[0], None, None, parts[0])
File "/opt/splunk/etc/apps/TA-symantec_atp/bin/email_symantec_util.py", line 6, in <module>
from . import logger_manager
File "/opt/splunk/etc/apps/splunk_rapid_diag/bin/logger_manager.py", line 14, in <module>
from rapid_diag.util import get_splunkhome_path, get_app_conf
ModuleNotFoundError: No module named 'rapid_diag'

And "/opt/splunk/var/log/splunk/web_service.log":

2021-09-22 13:24:03,700 ERROR [614b1253af7ff740791c10] utility:58 - name=javascript, class=Splunk.Error, lineNumber=272, message=Uncaught TypeError: Cannot read properties of undefined (reading 'data'), fileName=https://localhost:8443/en-US/static/@071D8440E5D1A785ECFF180D1ECF4589ACA117B332BB46A44AF934EFD3BCE24...
2021-09-22 13:24:05,706 ERROR [614b1255af7ff75b72bcd0] utility:58 - name=javascript, class=Splunk.Error, lineNumber=272, message=Uncaught TypeError: Cannot read properties of undefined (reading 'data'), fileName=https://localhost:8443/en-US/static/@071D8440E5D1A785ECFF180D1ECF4589ACA117B332BB46A44AF934EFD3BCE24...
2021-09-22 13:24:07,698 ERROR [614b1257ad7ff740411e50] utility:58 - name=javascript, class=Splunk.Error, lineNumber=272, message=Uncaught TypeError: Cannot read properties of undefined (reading 'data'), fileName=https://localhost:8443/en-US/static/@071D8440E5D1A785ECFF180D1ECF4589ACA117B332BB46A44AF934EFD3BCE24...
2021-09-22 13:24:09,702 ERROR [614b1259ae7ff740791790] utility:58 - name=javascript, class=Splunk.Error, lineNumber=272, message=Uncaught TypeError: Cannot read properties of undefined (reading 'data'), fileName=https://localhost:8443/en-US/static/@071D8440E5D1A785ECFF180D1ECF4589ACA117B332BB46A44AF934EFD3BCE24...

Background:
I'm currently using TA-symantec_atp v1.3.0 with Splunk 7.3.2 but I want to upgrade to Splunk 8.1.X and only TA-symantec_atp v1.5.0 is compatible with 8.1.x and above (python 3)

I've tried to install and configure v1.5.0 of the addon on several machines running Splunk 8.1.x but all resulted in same error described above. 

Does anybody had this TA working? 

Labels (1)
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...