All Apps and Add-ons

Splunk Add-on for Akamai: Why am I not getting an data when I implement TA_Akamai_SIEM integration?

anzianojackson
Engager

I've been trying to figure this out for a bit now. I've installed the TA_Akamai_SIEM_1.2.0 to ingest Akamai Kona WAF logs. I have tested the REST API via command line to pull SIEM data, but when I trying to implement it with the Splunk Add-on, no data comes back.

Error Message from UI:

Unable to initialize modular input "TA-Akamai_SIEM" defined inside the app "TA-Akamai_SIEM": Introspecting scheme=TA-Akamai_SIEM: script running failed (exited with code 127).

I'm running this on a 6.5.3 forwarder.

0 Karma
1 Solution

cpetterborg
SplunkTrust
SplunkTrust

This is probably caused by java not being installed on the server.

View solution in original post

end_es
Observer

is anyone know how to disable this input?

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

Where is the input defined? You should be able to disable it where it is defined.

If you have access to the command line on the machine, do:

splunk btool inputs list --debug | fgrep "<the input name>"

 Where the input is defined, you can go to the config file and delete the input, or disable it.

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

This is probably caused by java not being installed on the server.

Karthikeya
Communicator

@cpetterborg can you please help me how to install Java on our Splunk instance? 

 

0 Karma

cpetterborg
SplunkTrust
SplunkTrust

It is highly reliant on what your servers are like, but here is a google search that might help you to install Java on various systems for Splunk:

https://www.google.com/search?q=site%3Asplunk.com+install+java&sca_esv=2e83ef3dd22d1d30&sxsrf=AHTn8z...

0 Karma

anzianojackson
Engager

I heart you so much!

0 Karma

iamarkaprabha
Contributor

Hi ,

Yes cpetterborg is correct. I had faced the same issue while integrating Akamai and splunk. The main issue is Java path. The shell script was not able to execute the jar due to java path issue

0 Karma

adri2915
Observer

Hello, please, you could say, how resolve this problem? what do you actions you applicated? 

Thank you

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...