All Apps and Add-ons

Invalid key in stanza [Splunk_TA_f5_bigip_main]

gduggan1
Path Finder

I am running Splunk 6.3.3 and F5 TA 2.4.0 and getting the following error. Anyone seen this before? I am still indexing data from F5 so it can't be too critical....

Invalid key in stanza [Splunk_TA_f5_bigip_main] in /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/inputs.conf, line 12: start_by_shell (value: false).

btool debug
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/app.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/eventgen.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/eventtypes.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/f5_bigip_templates.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/inputs.conf
Invalid key in stanza [Splunk_TA_f5_bigip_main] in /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/inputs.conf, line 12: start_by_shell (value: false).
Did you mean 'source'?
Did you mean 'sourcetype'?
No spec file for: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/log_info.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/props.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/tags.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/transforms.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/web.conf

1 Solution

maikfischer
Engager

Hi,

as start_by_shell is an option for a script-stanza, try to rename the stanza "[Splunk_TA_f5_bigip_main]" to "[script://./bin/Splunk_TA_f5_bigip_main.py]".

regards,

Maik

View solution in original post

0 Karma

gduggan1
Path Finder

Thank you very much!

0 Karma

maikfischer
Engager

Hi,

as start_by_shell is an option for a script-stanza, try to rename the stanza "[Splunk_TA_f5_bigip_main]" to "[script://./bin/Splunk_TA_f5_bigip_main.py]".

regards,

Maik

0 Karma

jmantor
Path Finder

This stanza is still broken in version 2.5.0 of this app.
Could this get fixed upstream, please?

michael_kushma
Path Finder

Can we see the inputs.conf in question?

0 Karma

gduggan1
Path Finder

inputs.conf

[udp://9514]
disabled = false
connection_host=ip
sourcetype = f5:bigip:syslog

[tcp://9515]
disabled = false
connection_host=ip
sourcetype = f5:bigip:syslog

[Splunk_TA_f5_bigip_main]
start_by_shell = false

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...