All Apps and Add-ons

Splunk Add-on for F5 BIG-IP: Why am I unable to initialize the modular input?

stanhoener
Engager

Search peer has the following message: Unable to initialize modular input "Splunk_TA_f5_bigip_main" defined inside the app "Splunk_TA_f5-bigip": Unable to locate suitable script for introspection.

0 Karma

aagro
Path Finder

I have resovled this problem just only adding a comment for the stanza and attributes inside the config file inputs.conf.spec as showing below:

FILE => .../Splunk_TA_f5-bigip/README/inputs.conf.spec
# [Splunk_TA_f5_bigip_main://]

# nothing=nothing

Then restart splunk.

0 Karma

ragedsparrow
SplunkTrust
SplunkTrust

I work with Stan here and I was able to fix this by doing the following:

  • I removed the README/inputs.conf.spec filefor the app (since we were deploying on index clusters, there were no need for the inputs.conf on these servers).
  • I also commented out the stanza for the input in the default/log_info.conf .

After I pushed these changes to the IDX cluster, we stopped receiving the error message.

payamhaddad
New Member

do u use Universal Forwarder to receive data from F5 ? based on syslog ?

then how you send them to indexers ?
is the TA working on indexers?

0 Karma

sbbadri
Motivator

That error might because of wrong installation or configuration.

Check below link for hardware and software requirements.

http://docs.splunk.com/Documentation/AddOns/released/F5BIGIP/Hardwareandsoftwarerequirements

Hope this helps .

0 Karma

stanhoener
Engager

getting the above error when f5-bigip is loaded on to our index cluster peers.

0 Karma
Get Updates on the Splunk Community!

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...