All Apps and Add-ons

Invalid key in stanza [Splunk_TA_f5_bigip_main]

Explorer

I am running Splunk 6.3.3 and F5 TA 2.4.0 and getting the following error. Anyone seen this before? I am still indexing data from F5 so it can't be too critical....

Invalid key in stanza [SplunkTAf5bigipmain] in /opt/splunk/etc/apps/SplunkTAf5-bigip/default/inputs.conf, line 12: startbyshell (value: false).

btool debug
Checking: /opt/splunk/etc/apps/SplunkTAf5-bigip/default/app.conf
No spec file for: /opt/splunk/etc/apps/SplunkTAf5-bigip/default/eventgen.conf
Checking: /opt/splunk/etc/apps/SplunkTAf5-bigip/default/eventtypes.conf
No spec file for: /opt/splunk/etc/apps/SplunkTAf5-bigip/default/f5bigiptemplates.conf
Checking: /opt/splunk/etc/apps/SplunkTAf5-bigip/default/inputs.conf
Invalid key in stanza [SplunkTAf5bigipmain] in /opt/splunk/etc/apps/SplunkTAf5-bigip/default/inputs.conf, line 12: startbyshell (value: false).
Did you mean 'source'?
Did you mean 'sourcetype'?
No spec file for: /opt/splunk/etc/apps/SplunkTAf5-bigip/default/loginfo.conf
Checking: /opt/splunk/etc/apps/Splunk
TAf5-bigip/default/props.conf
Checking: /opt/splunk/etc/apps/Splunk
TAf5-bigip/default/tags.conf
Checking: /opt/splunk/etc/apps/Splunk
TAf5-bigip/default/transforms.conf
Checking: /opt/splunk/etc/apps/Splunk
TA_f5-bigip/default/web.conf

1 Solution

Engager

Hi,

as startbyshell is an option for a script-stanza, try to rename the stanza "[SplunkTAf5bigipmain]" to "[script://./bin/SplunkTAf5bigipmain.py]".

regards,

Maik

View solution in original post

0 Karma

Explorer

Thank you very much!

0 Karma

Engager

Hi,

as startbyshell is an option for a script-stanza, try to rename the stanza "[SplunkTAf5bigipmain]" to "[script://./bin/SplunkTAf5bigipmain.py]".

regards,

Maik

View solution in original post

0 Karma

Path Finder

This stanza is still broken in version 2.5.0 of this app.
Could this get fixed upstream, please?

Path Finder

Can we see the inputs.conf in question?

0 Karma

Explorer

inputs.conf

[udp://9514]
disabled = false
connection_host=ip
sourcetype = f5:bigip:syslog

[tcp://9515]
disabled = false
connection_host=ip
sourcetype = f5:bigip:syslog

[SplunkTAf5bigipmain]
startbyshell = false

0 Karma