All Apps and Add-ons
Highlighted

Splunk Health Check Overview: How can we remove messages from this app?

Path Finder

Getting "message from "python /opt/splunk/etc/slave-apps/SplunkTAaws/bin/splunktaaws_sqs.py" 'placeholder': {'title': 'placeholder'}" in health overview app in Splunk.

The SplunkTAaws on our instance is already disabled.

What can we modify to get rid of these messages.

Thanks.

0 Karma
Highlighted

Re: Splunk Health Check Overview: How can we remove messages from this app?

Path Finder

Can anyone help??

0 Karma
Highlighted

Re: Splunk Health Check Overview: How can we remove messages from this app?

Splunk Employee
Splunk Employee

You likely have inputs within the app still enabled. Do not disable the app. Disable the inputs instead. If you want to limit access to the splunkTAaws app, limit the access to certain roles instead.

And FYI, after disabling the splunkTAaws on my system, I was prompted that a restart is required. I re-enabled the splunkTAaws app first, then restart my system. Since then the disable app link/button is gone. So perhaps it's not meant to be disabled.

And one last note, make sure your splunkTAaws inputs are setup on a heavy forwarder, NOT on your search head.

0 Karma
Highlighted

Re: Splunk Health Check Overview: How can we remove messages from this app?

Path Finder

I have enabled the TA in our instance and we are still able to see the Disable button next to the TA.

Also, doesn't it mean that disabling the app will disable all the configurations related to it?

0 Karma
Highlighted

Re: Splunk Health Check Overview: How can we remove messages from this app?

Explorer

Hi.

I get this warnings in SPLUNK ES of a part of TA that we do not use. Any idea to get this turned off/disabled?

Search peer [servername role indexer ] has the following message: Unable to initialize modular input "splunktaawssqs" defined inside the app "SplunkTA_aws": Unable to locate suitable script for introspection.

0 Karma