I am using the Cisco Security Cloud integration in order to try and import my Duo logs into splunk enterprise (on prem). Following a plethora of directions, including Duo Splunk Connector guide I still cannot get it to work. No data goes through and it stays in a "Not Connected" status.
So far, I have verified that:
- Admin API token has correct permissions
- Integration is configured with correct admin api info like secret key, integration key, api hostname, etc.
- I am using the newest version of this app: Cisco Security Cloud
Does anyone have any tips for helping troubleshoot this issue? I cannot seem to find any logs or anything to even get a more advanced error code than "Not Connected" when I am pretty sure it should be working.
This splunk thread was the answer: https://community.splunk.com/t5/Knowledge-Management/Why-is-KV-Store-initialization-failing-on-one-o...
This splunk thread was the answer: https://community.splunk.com/t5/Knowledge-Management/Why-is-KV-Store-initialization-failing-on-one-o...
Hi @pc1
On your host with the inputs configured, do you see anything in $SPLUNK_HOME/var/log/splunk/splunkd.log relating to this input not running? Or is there a filename in the $SPLUNK_HOME/var/log/splunk/ relating to the app? What does this output when the modular input tries to run.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing