All Apps and Add-ons

Invalid key in stanza error for TA EdgeRouter X

Jon_Irish
Explorer

I just installed TA EdgeRouter X in hopes of getting the syslog data from my Ubiquity UniFi USG into CIM compliance. It installed fine, but when I start Splunk, I see this error:

Invalid key in stanza [syslog] in /Applications/Splunk/etc/apps/TA-EdgeRouter_X/default/props.conf, line 20: EVAl-direction (value: case(dest_zone="WAN" AND dest_interface="eth0", "outbound", src_zone="WAN" AND src_interface="eth0", "inbound", src_zone="LOCAL" AND (dest_interface="eth1.172" OR dest_interface="eth1.192" OR dest_interface="eth1.10" ), "local", dest_interface != "eth0", "local" )).

Anyone have an idea of might might be wrong?

TIA,
Jon

0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

This says evai not eval:

EVAl-direction

It's on line 20 in /Applications/Splunk/etc/apps/TA-EdgeRouter_X/default/props.conf

Change it to

EVAL-direction

And restart Splunk.

View solution in original post

jkat54
SplunkTrust
SplunkTrust

This says evai not eval:

EVAl-direction

It's on line 20 in /Applications/Splunk/etc/apps/TA-EdgeRouter_X/default/props.conf

Change it to

EVAL-direction

And restart Splunk.

jkat54
SplunkTrust
SplunkTrust

@jespencer

0 Karma

Jon_Irish
Explorer

That did it, thanks a lot!

0 Karma

jespencer
Engager

fixed the typo. thanks.

0 Karma
Get Updates on the Splunk Community!

Streamline Data Ingestion With Deployment Server Essentials

REGISTER NOW!Every day the list of sources Admins are responsible for gets bigger and bigger, often making the ...

Remediate Threats Faster and Simplify Investigations With Splunk Enterprise Security ...

REGISTER NOW!Join us for a Tech Talk around our latest release of Splunk Enterprise Security 7.2! We’ll walk ...

Introduction to Splunk AI

WATCH NOWHow are you using AI in Splunk? Whether you see AI as a threat or opportunity, AI is here to stay. ...