All Apps and Add-ons

Problem with reserved _id KV field

tofa
Explorer

Hi team,

I am running the latest Hurricane Labs Shodan version 2.0.8, but I am getting this error when running the saved search:

03-04-2021 13:50:53.754 ERROR KVStoreLookup - KV Store output failed with err: The _id field is a reserved field and may not be present in a document or query. message: 
03-04-2021 13:50:53.755 ERROR SearchResultsFiles - An error occurred while saving to the KV Store. Look at search.log for more information.
03-04-2021 13:50:53.755 ERROR outputcsv - sid:1614865793.691 Could not write to collection 'shodan_output': An error occurred while saving to the KV Store. Look at search.log for more information..

It looks like that, somehow, an _id field is being generated from the search

tofa_0-1614866434039.png

I could rename it of course, but I do not know how it is going to impact the rest of the app without troubleshooting it so I was wondering, how can I fix it quickly and, eventually, get the app updated to prevent such error on the next iterations?

Thanks and regards!

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...