All Apps and Add-ons

SA-SPLICE: Why am I getting "message from "python /opt/splunk/etc/apps/SA-Splice/bin/taxii.py" ERRORNo default database defined"?

chrisomar
New Member

Hello team,

I'm trying to get SPLICE working in Splunk, however, it's complaining about default database defined. Can someone please point me out to the right direction here.

thanks.

Tags (1)
0 Karma

cleroux_splunk
Splunk Employee
Splunk Employee

did you ran the setup to configure the mongo URI ? Everything you need should be in the embedded docs.

0 Karma

chrisomar
New Member

i did run config and i did configure the URI but I'm not sure how this works? the URI is for the mongoDB server IP? or where to poll the IOCs from the tool?

A little background, i have mongoDB in a different server - not in the search head like the docs recommend. I don't know how the communication work between the mongoDB, splunk and the tool where the IOCs are located. if you can help me understand that flow will be great.

thanks and I'm sorry for my novice in this regards.

0 Karma
Get Updates on the Splunk Community!

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureOn Demand Now Step boldly into the AI revolution with enhanced security ...

Enterprise Security Content Update (ESCU) | New Releases

In March, the Splunk Threat Research Team had 2 releases of security content via the Enterprise Security ...

Join the Splunk Developer Program Hackathon: Splunk Build-a-thon!

The Splunk Developer Program is launching in beta, and we’re celebrating with an exciting hackathon! This is ...