All Apps and Add-ons

Can you help me get the File/Directory Information Input working?

kozanic_FF
Path Finder

I'm trying to get the File/Directory Information Input app working but I'm struggling.

The place I'm working has this installed on a couple of heavy forwarders (HF), but neither seems to be generating any data. Looking in the internal logs, I can see the below error present from both HFs ( App version 1.1.2 running on these / Splunk 6.6):

ERROR ModularInputs - Introspecting scheme=file_meta_data: script running failed (exited with code 1).
ERROR ModularInputs - Unable to initialize modular input "file_meta_data" defined inside the app "file_meta_data": Introspecting scheme=file_meta_data: script running failed (exited with code 1).

I have also attempted to install and run on a new HF, which I have set-up but am getting a different error (latest App version 1.3 with Splunk 7.0.5):

uiHelper processValueEdit operator failed for endpoint_path=data/inputs/file_meta_data/FileMonitorTest elementName=spl-ctrl_sourcetypeSelect: list index out of range
uiHelper submitValueEdit operator failed for endpoint_base=data/inputs/file_meta_data entity_name=FileMonitorTest elementName=sourcetype: invalid syntax (<string>, line 1)

Not great with Python, so struggling to figure out how to resolve these issues.

Any assistance that can be provided would be great.

If additional information is required to assist - I'm happy to provide.

0 Karma
1 Solution

kozanic_FF
Path Finder

Not really sure what the issue was here, but after upgrading the add-on to the latest version and restarting splunk, things started working.

Assuming some Python issue which was fixed in a later version.

View solution in original post

kozanic_FF
Path Finder

Not really sure what the issue was here, but after upgrading the add-on to the latest version and restarting splunk, things started working.

Assuming some Python issue which was fixed in a later version.

Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...