All Apps and Add-ons

Will the Technology Add-on for Cisco Secure Access Control Server (ACS) be updated for compatibility with Splunk 6.3?

emartens
Explorer

Hi,

I like this add-on very much, but after the upgrade, it isn't compatible anymore with Splunk 6.3.
Is there a change that this APP is being upgraded?

Regards,
Ed Martens

tross33
Explorer

Ed,

Thank you very much for posting this to the board. The ACS TA is critical to our environment, and you thankfully alerted me to this issue prior to implementing the 6.3 upgrade. Does anyone have any information on a workaround, or information on an App upgrade?

Regards,

Tyler Ross

0 Karma

emartens
Explorer

Hi Tyler,

Data is correct in the search, however it not well formatted (eas of identify the different fields)

regards

0 Karma

dshpritz
SplunkTrust
SplunkTrust

Hello,

I'm not sure what you mean by this. I have installed the TA on 6.3 (not an upgrade) and the configurations are visible. Did this only happen after an upgrade? I'm sorry, I'm trying to reproduce the problem.

Thanks,

Dave

0 Karma

emartens
Explorer

I receive a 500 Internal server error..
https://LINK:8000/en-US/app/TA-cisco_acs/search/

0 Karma

emartens
Explorer

ps.
With 6.2 it was working after the upgrade it wasn't

0 Karma

dshpritz
SplunkTrust
SplunkTrust

Actually, that shouldn't work. This is an add-on, not an app. It is not meant to have a visual component. The extractions, eventtypes and tags are exported globally, so you should be able to use the fields in your other apps (like search or ES).

Thanks,

Dave

0 Karma

trross33
Path Finder

That is primarily my concern. We incorporate this data into ES, and have custom searches and alerts tied to field values, and ES tagged fields, so if the 6.3 update causes issues with the field extractions, this is my concern. Does anyone have any experience (positive or negative) with the upgrade to 6.3 (from 6.2.*) on a machine running the TA for ACS? Thanks everyone for the input, this is good information.

Tyler

0 Karma

dshpritz
SplunkTrust
SplunkTrust

Are you saying it isn't compatible because you tried it and something didn't work, or because the Splunkbase page doesn't list 6.3 as a supported version?

Thanks,

Dave

emartens
Explorer

Hi Dave,

The plugin doesn't work in the 6.3 version.
Previously I was working with the 6.2 and the plugin was working great.
But in the 6.3 it has been disappeared. Also after re-installing it again it is not working.

Thanks for the response

0 Karma

dshpritz
SplunkTrust
SplunkTrust

That's really strange. I haven't tested it with 6.3, and I don't have a solution off the top of my head. I'll see what I can do about getting more info.

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!