All Apps and Add-ons

Invalid key in stanza [Splunk_TA_f5_bigip_main]

gduggan1
Path Finder

I am running Splunk 6.3.3 and F5 TA 2.4.0 and getting the following error. Anyone seen this before? I am still indexing data from F5 so it can't be too critical....

Invalid key in stanza [Splunk_TA_f5_bigip_main] in /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/inputs.conf, line 12: start_by_shell (value: false).

btool debug
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/app.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/eventgen.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/eventtypes.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/f5_bigip_templates.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/inputs.conf
Invalid key in stanza [Splunk_TA_f5_bigip_main] in /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/inputs.conf, line 12: start_by_shell (value: false).
Did you mean 'source'?
Did you mean 'sourcetype'?
No spec file for: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/log_info.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/props.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/tags.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/transforms.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/web.conf

1 Solution

maikfischer
Engager

Hi,

as start_by_shell is an option for a script-stanza, try to rename the stanza "[Splunk_TA_f5_bigip_main]" to "[script://./bin/Splunk_TA_f5_bigip_main.py]".

regards,

Maik

View solution in original post

0 Karma

gduggan1
Path Finder

Thank you very much!

0 Karma

maikfischer
Engager

Hi,

as start_by_shell is an option for a script-stanza, try to rename the stanza "[Splunk_TA_f5_bigip_main]" to "[script://./bin/Splunk_TA_f5_bigip_main.py]".

regards,

Maik

0 Karma

jmantor
Path Finder

This stanza is still broken in version 2.5.0 of this app.
Could this get fixed upstream, please?

michael_kushma
Path Finder

Can we see the inputs.conf in question?

0 Karma

gduggan1
Path Finder

inputs.conf

[udp://9514]
disabled = false
connection_host=ip
sourcetype = f5:bigip:syslog

[tcp://9515]
disabled = false
connection_host=ip
sourcetype = f5:bigip:syslog

[Splunk_TA_f5_bigip_main]
start_by_shell = false

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...