All Apps and Add-ons

Why does SA-Faroo return an error message in the search window?

jbrodsky_splunk
Splunk Employee
Splunk Employee

After installing SA-Faroo and supplying the appropriate API key, why does the following message appear in the Splunk search window?

"The external search command 'faroo' did not return events in descending time order, as expected."

Tags (1)
0 Karma

jbrodsky_splunk
Splunk Employee
Splunk Employee

Interesting question, brodsky.

To fix, in the app, copy commands.conf from default to local. Then add the line "overrides_timeorder = true" at the end. No restart is necessary.

[faroo]
filename = faroo.py
streaming = true
passauth = true
overrides_timeorder = true

0 Karma
Get Updates on the Splunk Community!

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...