All Apps and Add-ons

Splunk Add-on for F5 BIG-IP: Why am I unable to initialize the modular input?

stanhoener
Engager

Search peer has the following message: Unable to initialize modular input "Splunk_TA_f5_bigip_main" defined inside the app "Splunk_TA_f5-bigip": Unable to locate suitable script for introspection.

0 Karma

aagro
Path Finder

I have resovled this problem just only adding a comment for the stanza and attributes inside the config file inputs.conf.spec as showing below:

FILE => .../Splunk_TA_f5-bigip/README/inputs.conf.spec
# [Splunk_TA_f5_bigip_main://]

# nothing=nothing

Then restart splunk.

0 Karma

ragedsparrow
Contributor

I work with Stan here and I was able to fix this by doing the following:

  • I removed the README/inputs.conf.spec filefor the app (since we were deploying on index clusters, there were no need for the inputs.conf on these servers).
  • I also commented out the stanza for the input in the default/log_info.conf .

After I pushed these changes to the IDX cluster, we stopped receiving the error message.

payamhaddad
New Member

do u use Universal Forwarder to receive data from F5 ? based on syslog ?

then how you send them to indexers ?
is the TA working on indexers?

0 Karma

sbbadri
Motivator

That error might because of wrong installation or configuration.

Check below link for hardware and software requirements.

http://docs.splunk.com/Documentation/AddOns/released/F5BIGIP/Hardwareandsoftwarerequirements

Hope this helps .

0 Karma

stanhoener
Engager

getting the above error when f5-bigip is loaded on to our index cluster peers.

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...