All Apps and Add-ons

Cisco Security Suite won't run because of "Possible typo in stanza [Cisco Security Suite ..."

stefanlasiewski
Contributor

I am running Splunk 5. When I restart Splunk, the Cisco Security Suite app is complaining about possible typos in my configuration files and now the app won't run.

I have never edited these files by hand, so I don't think I messed it up by hand. However, I did recently update from Cisco Security Suite 3.0.2 to 3.0.3 and I wonder if something bad happened during the upgrade.

Any ideas how I can recover from this error?

Update: I even tried uninstalling the App and I still get this error afterwards. After I uninstalled the app, I verified that /opt/splunk/etc/apps/Splunk_CiscoSecuritySuite didn't exist, and then reinstalled the app. The same problem still occurs.

[root@host ~]# splunk btool check
                Possible typo in stanza [Cisco Security Suite - Overview - Global Security Events Map] in /opt/splunk/etc/apps/Splunk_CiscoSecuritySuite/default/savedsearches.conf, line 7: display.general.enablePreview  =  true
                Possible typo in stanza [Cisco Security Suite - Overview - Global Security Events Map] in /opt/splunk/etc/apps/Splunk_CiscoSecuritySuite/default/savedsearches.conf, line 8: display.general.timeRangePicker.show   =  true
                Possible typo in stanza [Cisco Security Suite - Overview - Security Event Stats by Host] in /opt/splunk/etc/apps/Splunk_CiscoSecuritySuite/default/savedsearches.conf, line 16: display.general.enablePreview  =  true
                Possible typo in stanza [Cisco Security Suite - Overview - Security Event Stats by Host] in /opt/splunk/etc/apps/Splunk_CiscoSecuritySuite/default/savedsearches.conf, line 17: display.general.type  =  statistics
                Possible typo in stanza [Cisco Security Suite - Overview - Security Event Stats by Host] in /opt/splunk/etc/apps/Splunk_CiscoSecuritySuite/default/savedsearches.conf, line 18: display.general.timeRangePicker.show =  true
                ...
                ... SKIPED MANY LINES
                ...
                Possible typo in stanza [Cisco Security Suite - Overview - Top Threats] in /opt/splunk/etc/apps/Splunk_CiscoSecuritySuite/default/savedsearches.conf, line 83: display.visualizations.chartHeight  =  600px
                Possible typo in stanza [Cisco Security Suite - Overview - Top Threats] in /opt/splunk/etc/apps/Splunk_CiscoSecuritySuite/default/savedsearches.conf, line 84: display.visualizations.charting.chart =  pie
                Possible typo in stanza [Cisco Security Suite - Overview - Top Threats] in /opt/splunk/etc/apps/Splunk_CiscoSecuritySuite/default/savedsearches.conf, line 85: display.visualizations.charting.legend.placement =  right
[root@host ~]#
Tags (1)
0 Karma
1 Solution

stefanlasiewski
Contributor

Given the quiet response here, I don't think I can solve this without a ton more investigation and I don't have much time to spend on this problem.

I updated from Splunk 5 to Splunk 6. The error has now gone away. This makes me think that the root cause of this error was actually outside of the CSS application.

View solution in original post

stefanlasiewski
Contributor

Given the quiet response here, I don't think I can solve this without a ton more investigation and I don't have much time to spend on this problem.

I updated from Splunk 5 to Splunk 6. The error has now gone away. This makes me think that the root cause of this error was actually outside of the CSS application.

jconger
Splunk Employee
Splunk Employee

Very strange as those "possible typos" are all in savedsearches.conf and savedsearches.conf did not change from version 3.0.2 to 3.0.3. What version of Splunk are you running? Also, does anything look strange in savedsearches.conf (like extra characters)?

0 Karma

jconger
Splunk Employee
Splunk Employee

Version 3.x of the Cisco Security Suite was built for Splunk 6.x. Some parts will work on Splunk 5.x, but others will not.

0 Karma

stefanlasiewski
Contributor

I updated my question (see above). I was also able to work around this error by updating from Splunk 5 to Splunk 6.

0 Karma

stefanlasiewski
Contributor

savedsearches.conf looks completely fine to me. No strange whitespace issues, etc.

0 Karma

stefanlasiewski
Contributor

I am running Splunk 5. I will update to Splunk 6, but I figure I should first fix critical failures like this one before upgrading.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud | Unified Identity - Now Available for Existing Splunk ...

Raise your hand if you’ve already forgotten your username or password when logging into an account. (We can’t ...

Index This | How many sides does a circle have?

February 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

Registration for Splunk University is Now Open!

Are you ready for an adventure in learning?   Brace yourselves because Splunk University is back, and it's ...