All Apps and Add-ons

Installing Catalyst Center Add-on (Unable to initialize modular input)

_joe
Contributor

Hello all,

Upon installing the Cisco Catalyst Center Add-on, I immediately get the following error. I tried this on two separate servers, are there some undocumented requirements?

https://splunkbase.splunk.com/app/7858

RHEL8, Splunk Enterprise Version: 9.3.11

 

 

Unable to initialize modular input "cisco_catalyst_ise_analytics_reports" defined in the app "TA_cisco_catalyst": Introspecting scheme=cisco_catalyst_ise_analytics_reports: script running failed (PID 2484900 exited with code 1)..

 

Labels (1)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

Hello@_joe 

 

Usually there are one of these reasons for this error from any Add-on:

  • Add-on setup has not done yet
  • KVstore is not running or having issue
  • Add-on's code is having issue (Splunk compatibility issue, or missing prerequisite, etc)

 

I hope this helps!!!

View solution in original post

0 Karma

_joe
Contributor

I was able to determine the cause was the following config which I believe was affecting the interaction with the KVstore. 

## web.conf

cipherSuite = AES256-GCM-SHA384 
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @_joe 

Do you have any log files relating to Catalyst in $SPLUNK_HOME/var/log/splunk ? These might hold clues as to why this is failing. 

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Hello@_joe 

 

Usually there are one of these reasons for this error from any Add-on:

  • Add-on setup has not done yet
  • KVstore is not running or having issue
  • Add-on's code is having issue (Splunk compatibility issue, or missing prerequisite, etc)

 

I hope this helps!!!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...