All Apps and Add-ons

Invalid key in stanza [Splunk_TA_f5_bigip_main]

gduggan1
Path Finder

I am running Splunk 6.3.3 and F5 TA 2.4.0 and getting the following error. Anyone seen this before? I am still indexing data from F5 so it can't be too critical....

Invalid key in stanza [Splunk_TA_f5_bigip_main] in /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/inputs.conf, line 12: start_by_shell (value: false).

btool debug
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/app.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/eventgen.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/eventtypes.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/f5_bigip_templates.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/inputs.conf
Invalid key in stanza [Splunk_TA_f5_bigip_main] in /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/inputs.conf, line 12: start_by_shell (value: false).
Did you mean 'source'?
Did you mean 'sourcetype'?
No spec file for: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/log_info.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/props.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/tags.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/transforms.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/web.conf

1 Solution

maikfischer
Engager

Hi,

as start_by_shell is an option for a script-stanza, try to rename the stanza "[Splunk_TA_f5_bigip_main]" to "[script://./bin/Splunk_TA_f5_bigip_main.py]".

regards,

Maik

View solution in original post

0 Karma

gduggan1
Path Finder

Thank you very much!

0 Karma

maikfischer
Engager

Hi,

as start_by_shell is an option for a script-stanza, try to rename the stanza "[Splunk_TA_f5_bigip_main]" to "[script://./bin/Splunk_TA_f5_bigip_main.py]".

regards,

Maik

0 Karma

jmantor
Path Finder

This stanza is still broken in version 2.5.0 of this app.
Could this get fixed upstream, please?

michael_kushma
Path Finder

Can we see the inputs.conf in question?

0 Karma

gduggan1
Path Finder

inputs.conf

[udp://9514]
disabled = false
connection_host=ip
sourcetype = f5:bigip:syslog

[tcp://9515]
disabled = false
connection_host=ip
sourcetype = f5:bigip:syslog

[Splunk_TA_f5_bigip_main]
start_by_shell = false

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Synthetic Monitoring - Resolved Incident on Detector Alerts

We’ve discovered a bug that affected the auto-clear of Synthetic Detectors in the Splunk Synthetic Monitoring ...

Video | Tom’s Smartness Journey Continues

Remember Splunk Community member Tom Kopchak? If you caught the first episode of our Smartness interview ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud? Learn how unique features like ...