I just got done deploying Splunk 6, and it turns out that the couple of inputs I had using this plugin are now broken.
One of the scripts being used calls out to another server via SSH and formats the output like this:
Ready,100 Not Ready,54
After the upgrade, the indexed output looks like:
ssh: /opt/splunk/lib/libcrypto.so.1.0.0: version `OPENSSL_1.0.0' not found (required by ssh) ssh: /opt/splunk/lib/libcrypto.so.1.0.0: version `OPENSSL_1.0.0' not found (required by ssh) Ready, Not Ready,
Further, the "Command" option under Inputs is no longer there, meaning I can no longer configure this source.
Any idea what I need to do in order to fix this?
I'm having a similar problem with the Asset Discovery app. It appears Splunk 6 does not come with the right OpenSSL library.
You're going to have to do a workaround by changing your external commands. You can change the call to ssh if you're using bash from:
ssh abc defg hijk
LD_LIBRARY_PATH=/usr/lib:$LD_LIBRARY_PATH ssh abc defg hijk
if you're using Linux, to make sure the OS checks the default system path before it the Splunk path. If you have multiple calls to ssh or other commands that use openssl shared libraries, you can instead just
export LD_LIBRARY_PATH=/usr/lib:$LD_LIBRARY_PATH at the top of your script instead.
Also to add....
The Command Modular Input not showing up is due to a bug caused by the DB Connect app that causes all Modular Inputs , although they are installed and working fine, to not show up in the Manager UI. You can still browse to the Mod Input setup manually.
This bug is currently being fixed.
@richgalloway can you open a new question on that and include error messages? I'm collecting issues now and am opening an internal bug.