All Apps and Add-ons

IP Reputation app directory structure error.

prithvi08
Engager

I recently tried to install the ip reputation application to spunk enterprise. i had downloaded the .tgz file from splunkbase and tried to install by uploading to the file. i received the following error.

"There was an error processing the upload.Invalid app contents: archive contains more than one immediate subdirectory: and ipreputation"

so i extracted the file and checked that there was a another folder called PaxHeader as well as a file ._ipreputation under the ipreputation main directory. when i moved this file and folder into the ipreputation folder,the app seemed to be installed. But the threatscore was not displayed eventhough i had entered the key in the .py file. Please advise. I had re downloaded and checked for the MD5 checksum, it seems to be alright. but the app directory structure seems to have an error.

0 Karma
1 Solution

mayurr98
Super Champion

hey
You can't install this app via the GUI as the tgz file contains multiple apps (dependencies). You'll need to extract the tgz file within /opt/splunk/etc/apps (if not using a cluster) and restart splunk.

I hope this helps you!

View solution in original post

prithvi08
Engager

Thank you,seems to have installed fine.

0 Karma

mayurr98
Super Champion

you are welcome pls upvote as well!

0 Karma

mayurr98
Super Champion

hey
You can't install this app via the GUI as the tgz file contains multiple apps (dependencies). You'll need to extract the tgz file within /opt/splunk/etc/apps (if not using a cluster) and restart splunk.

I hope this helps you!

Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...