All Apps and Add-ons

Not getting any data from Google Apps for Splunk

hlarimer
Communicator

I have set up the Google Apps for Splunk app and successfully went through the configuration steps, but I'm not seeing any data. There are 3 inputs set up that I believe were there by default (this app was already installed when I took over this instance), but I'm wondering if they are correct or if there are other inputs that needed to be added. Any tips on getting data in?

Tags (1)
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

After an extensive webex, I discovered that the modular input was configured with an UPPER CASE domain. The credential was configured with lower case domain. Due to case sensitivity of the filesystem (*nix), the credentials were not found since the file didn't exist with upper case.

RESOLUTION: I will be enforcing lower case programatically when looking for and creating the credential file.

Thanks for the remote session @hlarimer!

EDIT: v1.1.3 has the update. Let me know of any other issues! Thanks!

View solution in original post

alacercogitatus
SplunkTrust
SplunkTrust

After an extensive webex, I discovered that the modular input was configured with an UPPER CASE domain. The credential was configured with lower case domain. Due to case sensitivity of the filesystem (*nix), the credentials were not found since the file didn't exist with upper case.

RESOLUTION: I will be enforcing lower case programatically when looking for and creating the credential file.

Thanks for the remote session @hlarimer!

EDIT: v1.1.3 has the update. Let me know of any other issues! Thanks!

MuS
SplunkTrust
SplunkTrust

Nice hint @alacercogitatus! Will enforce the same in my modular inputs from now on - thanks.

0 Karma

hlarimer
Communicator

Thanks again for the help @alacercogitatus

0 Karma

ontkanin
Path Finder

Thanks @alacercogitatus

0 Karma

ontkanin
Path Finder

Doesn't work for me either. It used to work, but it looks like one of the Splunk upgrades broke it. Or at least that's what it looks like in my case.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

@ontkanin: contact me directly, I'll have a look. I'm working with @hlarimer this morning to debug this question.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...