All Apps and Add-ons

Why do I see a script error when then the data is not received in Cisco eStreamer eNcore Add-on for Splunk?

lakshman239
Influencer

Installed the Add-on as per eStreamereNcoreOperationsGuide_30.pdf operations guide ( Thanks doughlas for the details). when there is no data received from the sourcefire, we still see the error message "msg="A script exited abnormally" input="./bin/splencore.sh clean" stanza="default" status="exited with code 1". would this go when the data is received or is this an issue?

0 Karma
1 Solution

lakshman239
Influencer

Yes, we had our install in a diff dir from '/opt', so had to update splencore.sh SPLUNK_HOME env variable and datfilespath as per our install directory. Then updated clean() function to check for a dir/files (datafilespath) before deleting the log files, as when there are no log/data files, the clean runs and fails.

View solution in original post

0 Karma

douglashurd
Builder

BTW, 3.5.4 is now the latest version. Bug fixes and huge performance improvements for multi-core installations. New docs too.

0 Karma

lakshman239
Influencer

Yes, we had our install in a diff dir from '/opt', so had to update splencore.sh SPLUNK_HOME env variable and datfilespath as per our install directory. Then updated clean() function to check for a dir/files (datafilespath) before deleting the log files, as when there are no log/data files, the clean runs and fails.

0 Karma

douglashurd
Builder

did you get this resolved?

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...