All Apps and Add-ons

Modular input error on defender-atp-hunting

dyeyniyel
Explorer

I'm getting below error for the TA-defender-atp-hunting on our HF.

Unable to initialize modular input "defender_hunting_query" defined in the app "TA-defender-atp-hunting": Introspecting scheme=defender_hunting_query: script running failed (exited with code 1)..

splunkd logs

ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':  The script at path=/opt/splunk/etc/apps/TA-defender-atp-hunting/bin/TA_defender_atp_hunting_rh_defender_hunting_query.py has thrown an exception=Traceback (most recent call last)

10-06-2021 03:20:48.823 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':File "/opt/splunk/bin/runScript.py", line 82, in <module>
10-06-2021 03:20:48.823 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':exec(open(REAL_SCRIPT_NAME).read())
10-06-2021 03:20:48.823 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':File "<string>", line 4, in <module>
10-06-2021 03:20:48.823 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':File "/opt/splunk/etc/apps/TA-defender-atp-hunting/bin/ta_defender_atp_hunting/splunktaucclib/rest_handler/endpoint/validator.py", line 388
10-06-2021 03:20:48.823 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':except ValueError, exc:
10-06-2021 03:20:48.823 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':                       ^
10-06-2021 03:20:48.823 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':SyntaxError: invalid syntax
10-06-2021 03:20:48.824 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':Traceback (most recent call last):
10-06-2021 03:20:48.824 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':File "/opt/splunk/bin/runScript.py", line 82, in <module>
10-06-2021 03:20:48.824 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':exec(open(REAL_SCRIPT_NAME).read())
10-06-2021 03:20:48.824 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':File "<string>", line 4, in <module>
10-06-2021 03:20:48.824 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':File "/opt/splunk/etc/apps/TA-defender-atp-hunting/bin/ta_defender_atp_hunting/splunktaucclib/rest_handler/endpoint/validator.py", line 388
10-06-2021 03:20:48.824 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':except ValueError, exc:
10-06-2021 03:20:48.824 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':                       ^
10-06-2021 03:20:48.824 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':SyntaxError: invalid syntax
10-06-2021 03:20:48.828 +0000 ERROR AdminManagerExternal - External handler failed with code '1' and output: ''.  See splunkd.log for stderr output.

I'm not able to access the defender atp hunting app via UI. Would anyone know how to resolve this issue? 

Thanks in advance!

Labels (3)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...