All Apps and Add-ons

Why is the TA-forwarderquery Add-on missing files that are referenced in commands.conf?

tlmayes
Contributor

Does this App actually work "as-is"? Installed in a Search Head cluster environment and then went through the files from the provided tar file. Specifically the file "commands.conf" references 4 python files


[forwarderquery]
filename = forwarderquery.py

[forwarderquery2]
filename = forwarderquery2.py

[forwarderconfig]
filename = forwarderconfig.py

[splunkrestlookup]
filename = lookup_splunkrest.py

These files do not exist, within the provided downloaded App, within the Search Heads, or within the Universal Forwarders (I assumed that maybe existing Splunk resources were being leveraged).

Am I missing something, or is this app DOA?

See y'all at the conference in Oct.....

0 Karma

dominiquevocat
SplunkTrust
SplunkTrust

Because i missed out removing the references.
Were you specifically missing them or why do you conclude it does not work?

0 Karma

dmaislin_splunk
Splunk Employee
Splunk Employee

I assume you are referencing the https://splunkbase.splunk.com/app/2775/ app which is the TA-forwarderquery. I see that in this specific app it contains a forwarderquery.py in the bin directory of this TA.

This App is not created or supported by Splunk, but by someone who is a Splunk app developer, Dominique Vocat . You can reach out to them on the app page for additional support.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...