All Apps and Add-ons

Splunk for Cisco Security App Install error

ryanbyrdbasicre
Engager

I want to install Splunk for Cisco Security App

I used downloaded http://www.splunkbase.com/apps/All/4.x/App/app:Splunk+for+Cisco+Security and unzip/untared the file to /opt/splunk/etc/apps. I'm running splunk version 4.0.11, build 79031 on linux

then I chown the files to splunk and chmod them to 755

the I restart splunk (service splunk stop; service splunk start)

when i log into the web interface and click the Cisco Security App icon, I get a page with 3 javascript alert popups: Splunk encountered the following unknown module: "ConvertToDrilldownSearch" . The view may not load properly.

as well, in red, at the top of the screen is: Misconfigured view 'gc_overview' - Unknown parameter 'drilldown' is defined for module SimpleResultsTable. Make sure the parameter is specified in SimpleResultsTable.conf.

ideas?

Tags (2)
1 Solution

ziegfried
Influencer

Drilldown is a feature that was introduced in Splunk 4.1. Seems like the Cisco Security app uses this features in some views and hence is not compatible with 4.0.x. Your best bet is to upgrade your Splunk installation.

View solution in original post

ziegfried
Influencer

Drilldown is a feature that was introduced in Splunk 4.1. Seems like the Cisco Security app uses this features in some views and hence is not compatible with 4.0.x. Your best bet is to upgrade your Splunk installation.

Get Updates on the Splunk Community!

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...