All Apps and Add-ons

Invalid key in stanza [Splunk_TA_f5_bigip_main]

gduggan1
Path Finder

I am running Splunk 6.3.3 and F5 TA 2.4.0 and getting the following error. Anyone seen this before? I am still indexing data from F5 so it can't be too critical....

Invalid key in stanza [Splunk_TA_f5_bigip_main] in /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/inputs.conf, line 12: start_by_shell (value: false).

btool debug
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/app.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/eventgen.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/eventtypes.conf
No spec file for: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/f5_bigip_templates.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/inputs.conf
Invalid key in stanza [Splunk_TA_f5_bigip_main] in /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/inputs.conf, line 12: start_by_shell (value: false).
Did you mean 'source'?
Did you mean 'sourcetype'?
No spec file for: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/log_info.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/props.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/tags.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/transforms.conf
Checking: /opt/splunk/etc/apps/Splunk_TA_f5-bigip/default/web.conf

1 Solution

maikfischer
Engager

Hi,

as start_by_shell is an option for a script-stanza, try to rename the stanza "[Splunk_TA_f5_bigip_main]" to "[script://./bin/Splunk_TA_f5_bigip_main.py]".

regards,

Maik

View solution in original post

0 Karma

gduggan1
Path Finder

Thank you very much!

0 Karma

maikfischer
Engager

Hi,

as start_by_shell is an option for a script-stanza, try to rename the stanza "[Splunk_TA_f5_bigip_main]" to "[script://./bin/Splunk_TA_f5_bigip_main.py]".

regards,

Maik

0 Karma

jmantor
Path Finder

This stanza is still broken in version 2.5.0 of this app.
Could this get fixed upstream, please?

michael_kushma
Path Finder

Can we see the inputs.conf in question?

0 Karma

gduggan1
Path Finder

inputs.conf

[udp://9514]
disabled = false
connection_host=ip
sourcetype = f5:bigip:syslog

[tcp://9515]
disabled = false
connection_host=ip
sourcetype = f5:bigip:syslog

[Splunk_TA_f5_bigip_main]
start_by_shell = false

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...