All Apps and Add-ons

Splunk for Cisco Security App Install error

ryanbyrdbasicre
Engager

I want to install Splunk for Cisco Security App

I used downloaded http://www.splunkbase.com/apps/All/4.x/App/app:Splunk+for+Cisco+Security and unzip/untared the file to /opt/splunk/etc/apps. I'm running splunk version 4.0.11, build 79031 on linux

then I chown the files to splunk and chmod them to 755

the I restart splunk (service splunk stop; service splunk start)

when i log into the web interface and click the Cisco Security App icon, I get a page with 3 javascript alert popups: Splunk encountered the following unknown module: "ConvertToDrilldownSearch" . The view may not load properly.

as well, in red, at the top of the screen is: Misconfigured view 'gc_overview' - Unknown parameter 'drilldown' is defined for module SimpleResultsTable. Make sure the parameter is specified in SimpleResultsTable.conf.

ideas?

Tags (2)
1 Solution

ziegfried
Influencer

Drilldown is a feature that was introduced in Splunk 4.1. Seems like the Cisco Security app uses this features in some views and hence is not compatible with 4.0.x. Your best bet is to upgrade your Splunk installation.

View solution in original post

ziegfried
Influencer

Drilldown is a feature that was introduced in Splunk 4.1. Seems like the Cisco Security app uses this features in some views and hence is not compatible with 4.0.x. Your best bet is to upgrade your Splunk installation.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...