All Apps and Add-ons

Cloud Support - addon fails vetting

ChrisBell04
Communicator

When will the Cisco ACI addon support Cloud? It fails app vetting for the following reasons.

This is a preliminary report. More issues may be found upon further review. 
Thank you for your app install request. Your app did not meet security and functionality requirements for Splunk Cloud for the following reasons: 
Blocking issue:
1. The private key is displayed as plain text in this app which is not permitted in Splunk Cloud. Please remove this file. File: bin/websocket_client-0.35.0-py2.7.egg/websocket/privkey.pem.
2. The "cookie" containing privatekey was loged to local file, which is not permmited in spluk cloud. Please remove the privatekey in cookie. File: bin/acisession.py, line: 605.
3. The arguments field of input in setup page is vulnerable to xxs attack. Please validate or escape user input before saving. File: appserver/static/application.js.
Non-blocking issue:
1. Setup configures non-search-head features: inputs. File: default/setup.xml.
Once issues are remedied  you can submit your app to review.
0 Karma

woodcock
Esteemed Legend

You have to contact Cisco. The app says this:

SUPPORT
• This app is supported by Cisco Systems.
• Please ask questions by creating a TAC case on https://globalcontacts.cloudapps.cisco.com/contacts/contactDetails/en_US/c1o1-c2o2-c3o8 OR contact us at 1 800 553 2447 or 1 408 526 7209
• Alternatively, send us an email to aci-splunk-app@cisco.com
0 Karma

ChrisBell04
Communicator

Indeed. Blasting all channels of communication in attempt to get their attention.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...