All Apps and Add-ons

Running Browsing History Analysis on Windows with just a Universal Forwarder

realgandy
Explorer

Can you give details of how to get this to work on Windows that is only running a universal forwarder? I have installed a local copy of python, but the log gives the following errors:

 05-02-2014 16:17:43.474 +0100 ERROR ExecProcessor - message from "python "C:\Program Files\SplunkUniversalForwarder\etc\apps\browsers\bin\monitor.py""   File "C:\Program Files\SplunkUniversalForwarder\etc\apps\browsers\bin\monitor.py", line 60
05-02-2014 16:17:43.474 +0100 ERROR ExecProcessor - message from "python "C:\Program Files\SplunkUniversalForwarder\etc\apps\browsers\bin\monitor.py""     except Exception,e:
05-02-2014 16:17:43.474 +0100 ERROR ExecProcessor - message from "python "C:\Program Files\SplunkUniversalForwarder\etc\apps\browsers\bin\monitor.py""                     ^
05-02-2014 16:17:43.474 +0100 ERROR ExecProcessor - message from "python "C:\Program Files\SplunkUniversalForwarder\etc\apps\browsers\bin\monitor.py"" SyntaxError: invalid syntax

Any thoughts on this please?

Thanks

0 Karma

MarioM
Motivator

the problem is that the monitor.py use 2 splunk python libraries:

import splunk.bundle as bundle
import splunk.util as util

And the universal forwarder doesnot have python or those librarie which you can find in a full splunk installation:

util.py

splunk_home\lib\python2.7\ctypes\

bundle.py

splunk_home\lib\python2.7\site-packages\splunk\clilib\
0 Karma

psbailey86
Explorer

I am having this exact issue with the latest version. Were you ever able to find a fix for this using a Windows Universal Forwarder?

Thanks!

MarioM
Motivator

you could try by putting those util.py... and bundle.py... in splunk_home\etc\apps\browsers\bin\

0 Karma

realgandy
Explorer

Are you saying it can't be done then.

Am I right to assume that those libraries require the full splunk installation for this app to work?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...