All Apps and Add-ons

Not getting any data from Google Apps for Splunk

hlarimer
Communicator

I have set up the Google Apps for Splunk app and successfully went through the configuration steps, but I'm not seeing any data. There are 3 inputs set up that I believe were there by default (this app was already installed when I took over this instance), but I'm wondering if they are correct or if there are other inputs that needed to be added. Any tips on getting data in?

Tags (1)
1 Solution

alacercogitatus
SplunkTrust
SplunkTrust

After an extensive webex, I discovered that the modular input was configured with an UPPER CASE domain. The credential was configured with lower case domain. Due to case sensitivity of the filesystem (*nix), the credentials were not found since the file didn't exist with upper case.

RESOLUTION: I will be enforcing lower case programatically when looking for and creating the credential file.

Thanks for the remote session @hlarimer!

EDIT: v1.1.3 has the update. Let me know of any other issues! Thanks!

View solution in original post

alacercogitatus
SplunkTrust
SplunkTrust

After an extensive webex, I discovered that the modular input was configured with an UPPER CASE domain. The credential was configured with lower case domain. Due to case sensitivity of the filesystem (*nix), the credentials were not found since the file didn't exist with upper case.

RESOLUTION: I will be enforcing lower case programatically when looking for and creating the credential file.

Thanks for the remote session @hlarimer!

EDIT: v1.1.3 has the update. Let me know of any other issues! Thanks!

MuS
SplunkTrust
SplunkTrust

Nice hint @alacercogitatus! Will enforce the same in my modular inputs from now on - thanks.

0 Karma

hlarimer
Communicator

Thanks again for the help @alacercogitatus

0 Karma

ontkanin
Path Finder

Thanks @alacercogitatus

0 Karma

ontkanin
Path Finder

Doesn't work for me either. It used to work, but it looks like one of the Splunk upgrades broke it. Or at least that's what it looks like in my case.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

@ontkanin: contact me directly, I'll have a look. I'm working with @hlarimer this morning to debug this question.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...