All Apps and Add-ons

Splunk Add-on for F5 BIG-IP: Why am I unable to initialize the modular input?

stanhoener
Engager

Search peer has the following message: Unable to initialize modular input "Splunk_TA_f5_bigip_main" defined inside the app "Splunk_TA_f5-bigip": Unable to locate suitable script for introspection.

0 Karma

aagro
Path Finder

I have resovled this problem just only adding a comment for the stanza and attributes inside the config file inputs.conf.spec as showing below:

FILE => .../Splunk_TA_f5-bigip/README/inputs.conf.spec
# [Splunk_TA_f5_bigip_main://]

# nothing=nothing

Then restart splunk.

0 Karma

ragedsparrow
Contributor

I work with Stan here and I was able to fix this by doing the following:

  • I removed the README/inputs.conf.spec filefor the app (since we were deploying on index clusters, there were no need for the inputs.conf on these servers).
  • I also commented out the stanza for the input in the default/log_info.conf .

After I pushed these changes to the IDX cluster, we stopped receiving the error message.

payamhaddad
New Member

do u use Universal Forwarder to receive data from F5 ? based on syslog ?

then how you send them to indexers ?
is the TA working on indexers?

0 Karma

sbbadri
Motivator

That error might because of wrong installation or configuration.

Check below link for hardware and software requirements.

http://docs.splunk.com/Documentation/AddOns/released/F5BIGIP/Hardwareandsoftwarerequirements

Hope this helps .

0 Karma

stanhoener
Engager

getting the above error when f5-bigip is loaded on to our index cluster peers.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...