All Apps and Add-ons

How come my Cb Defense Add-on won't load and is returning the following "Unable to initialize modular input" failure message?

jflaherty
Path Finder

I am unable to get the Cb Defense Add-on to load. This is in a fresh version of Splunk 7.1.3.

I Install the add-on, restart Splunk, click on the add-on link and it just sits there with a"loading" indicator but then never loads. It also eventually gives;

Unable to initialize modular input "carbonblack_defense" defined inside the app "TA-Cb_Defense": Introspecting scheme=carbonblack_defense: script running failed (exited with code 1).

Thanks

0 Karma
1 Solution

wfjarrett538
Explorer

If you are that far, you found the typo in props.conf in 2.0.2? That was stopping Splunk from starting at all after I installed this app.

I'm not sure what is causing that error you are seeing - I know if you remove the README/inputs.conf.spec file it goes away.

Anyways, are you using 2.0.2? When I went to download the add-on a couple of weeks ago, 2.0.2 was the default. Now, 2.0.1 is the default, and 2.0.2 is still available and gives the warning, "This version has not passed Splunk AppInspect."

I guess the short answer is if you are using 2.0.2, try 2.0.1. It seems a lot less broken.

View solution in original post

0 Karma

wfjarrett538
Explorer

If you are that far, you found the typo in props.conf in 2.0.2? That was stopping Splunk from starting at all after I installed this app.

I'm not sure what is causing that error you are seeing - I know if you remove the README/inputs.conf.spec file it goes away.

Anyways, are you using 2.0.2? When I went to download the add-on a couple of weeks ago, 2.0.2 was the default. Now, 2.0.1 is the default, and 2.0.2 is still available and gives the warning, "This version has not passed Splunk AppInspect."

I guess the short answer is if you are using 2.0.2, try 2.0.1. It seems a lot less broken.

0 Karma

jflaherty
Path Finder

I was using 2.0.2. I didn't realize that it was broken. I tried 2.0.1 and everything is working good now. Thank you!

0 Karma

OBsecurity
Explorer

thanks for your help!

0 Karma

OBsecurity
Explorer

having the same issue.
anyone pls?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...