All Apps and Add-ons

Not getting any data from Google Apps for Splunk

hlarimer
Communicator

I have set up the Google Apps for Splunk app and successfully went through the configuration steps, but I'm not seeing any data. There are 3 inputs set up that I believe were there by default (this app was already installed when I took over this instance), but I'm wondering if they are correct or if there are other inputs that needed to be added. Any tips on getting data in?

Tags (1)
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

After an extensive webex, I discovered that the modular input was configured with an UPPER CASE domain. The credential was configured with lower case domain. Due to case sensitivity of the filesystem (*nix), the credentials were not found since the file didn't exist with upper case.

RESOLUTION: I will be enforcing lower case programatically when looking for and creating the credential file.

Thanks for the remote session @hlarimer!

EDIT: v1.1.3 has the update. Let me know of any other issues! Thanks!

View solution in original post

alacercogitatus
SplunkTrust
SplunkTrust

After an extensive webex, I discovered that the modular input was configured with an UPPER CASE domain. The credential was configured with lower case domain. Due to case sensitivity of the filesystem (*nix), the credentials were not found since the file didn't exist with upper case.

RESOLUTION: I will be enforcing lower case programatically when looking for and creating the credential file.

Thanks for the remote session @hlarimer!

EDIT: v1.1.3 has the update. Let me know of any other issues! Thanks!

MuS
SplunkTrust
SplunkTrust

Nice hint @alacercogitatus! Will enforce the same in my modular inputs from now on - thanks.

0 Karma

hlarimer
Communicator

Thanks again for the help @alacercogitatus

0 Karma

ontkanin
Path Finder

Thanks @alacercogitatus

0 Karma

ontkanin
Path Finder

Doesn't work for me either. It used to work, but it looks like one of the Splunk upgrades broke it. Or at least that's what it looks like in my case.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

@ontkanin: contact me directly, I'll have a look. I'm working with @hlarimer this morning to debug this question.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...