All Apps and Add-ons

Why do I see a script error when then the data is not received in Cisco eStreamer eNcore Add-on for Splunk?

lakshman239
Influencer

Installed the Add-on as per eStreamereNcoreOperationsGuide_30.pdf operations guide ( Thanks doughlas for the details). when there is no data received from the sourcefire, we still see the error message "msg="A script exited abnormally" input="./bin/splencore.sh clean" stanza="default" status="exited with code 1". would this go when the data is received or is this an issue?

0 Karma
1 Solution

lakshman239
Influencer

Yes, we had our install in a diff dir from '/opt', so had to update splencore.sh SPLUNK_HOME env variable and datfilespath as per our install directory. Then updated clean() function to check for a dir/files (datafilespath) before deleting the log files, as when there are no log/data files, the clean runs and fails.

View solution in original post

0 Karma

douglashurd
Builder

BTW, 3.5.4 is now the latest version. Bug fixes and huge performance improvements for multi-core installations. New docs too.

0 Karma

lakshman239
Influencer

Yes, we had our install in a diff dir from '/opt', so had to update splencore.sh SPLUNK_HOME env variable and datfilespath as per our install directory. Then updated clean() function to check for a dir/files (datafilespath) before deleting the log files, as when there are no log/data files, the clean runs and fails.

0 Karma

douglashurd
Builder

did you get this resolved?

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...