All Apps and Add-ons

Why can I not produce an alert in the integration of ForeScout App for Splunk?

gsales
New Member

Hi,

We are encountering a problem integrating ForeScout in Splunk. We installed the following:

  • ForeScout App for Splunk v2.7.0_2
  • ForeScout Adaptive Response Add-on for Splunk v2.7.0_2
  • ForeScout Technology Add-on for Splunk v2.7.0

We cannot produce an alert since it is encountering a Read operation timed out.
Appreciate your help. Thank you.

Please see below screenshot.
alt text

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@gsales,

I faced same issue. I found that there are so many background processes running by splunkd. I have configured so many apps and ES which cause splunkd slow to respond on immediate basis. So I think you have to check installed apps in that particular instance and do setup after disable app such apps if possible.

0 Karma

xpac
SplunkTrust
SplunkTrust

Hey,

the add-on seems to do something by contacting splunkd's REST API, which times out in your case.
Did you, by any chance, setup any firewall rules that might influence network connectivity?

Hope that helps - if it does I'd be happy if you would upvote/accept this answer, so others could profit from it. 🙂

0 Karma

gsales
New Member

Hi there xpac,

Thanks for your reply. Will ask the client about their network connectivity.
Will update as soon as we have a feedback.

Thank you.

0 Karma

xpac
SplunkTrust
SplunkTrust

This might be a local connection, i.e. the app tries to contact splunkd running on the same server. Usually such connectivity is not firewalled, but everything is possible. 😉

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...