All Apps and Add-ons

Install Problem

donforbes
Engager

Hi. I am having difficulty getting the PCI app to install. The app itself is installed and works fine, but I dont seem to be gettingthing in the views. Can you help?

1 Solution

Pete_Bassill
Path Finder

Afternoon.

Are you at the Splunk user conf? If you are come and find me and I will walk you through it. If not, can you be more specific on the errors you are encountering?

The vast majority of the rules are inline rules within the XML views. All but one of the XML views use the simple XML syntax so that they can be easily edited as required. The only expection to this is the amMap module, which is an implementation of the amMap application.

You will need to install the geoip app too, it is important for the location lookups and the amMap relies on it.

I am hoping to get some docs around the app produced soon. If you can provide more information, I will do my best to help.

Pete

View solution in original post

Pete_Bassill
Path Finder

Afternoon.

Are you at the Splunk user conf? If you are come and find me and I will walk you through it. If not, can you be more specific on the errors you are encountering?

The vast majority of the rules are inline rules within the XML views. All but one of the XML views use the simple XML syntax so that they can be easily edited as required. The only expection to this is the amMap module, which is an implementation of the amMap application.

You will need to install the geoip app too, it is important for the location lookups and the amMap relies on it.

I am hoping to get some docs around the app produced soon. If you can provide more information, I will do my best to help.

Pete

donforbes
Engager

Thanks, the geoip app install fixed the issue.

  • don
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...