All Apps and Add-ons

Splunk Addon Builder app automatically adds a data input.

spamarea1
Observer

Addon Builder 4.5.0.

This app adds a data input automatically. This is a good thing, I then go to add new to complete the configuration. Everything is running good.

A few days later, I thought of a better name for the input. I cloned the original, put a different name, and kept all the same config.

I disabled the original.

I noticed that I can still run the script and see the API output, but when I searched for the output, I did not find it. I started to see 401 errors instead. I went back to the data inputs and disabled the clone and enabled the original and all is back to normal.

Is there a rule to cloning the data input for the addon builder that says not to clone?

 

 

 

Labels (1)
0 Karma

livehybrid
Ultra Champion

Hi @spamarea1 

Do you have any encrypted fields in the input configuration? It might be that these arent copied when an input is cloned - this might explain why you are getting a 401 error from your API if its missing some credentials/password etc.

If you've clone it, try updating any encrypted value - if appropriate.

:glowing_star: Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma

spamarea1
Observer

Thanks for replying but no encryption. I used the modular frame of the python script that it gave me as a template.

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...