Archive

Splunk for Cisco Security App Install error

I want to install Splunk for Cisco Security App

I used downloaded http://www.splunkbase.com/apps/All/4.x/App/app:Splunk+for+Cisco+Security and unzip/untared the file to /opt/splunk/etc/apps. I'm running splunk version 4.0.11, build 79031 on linux

then I chown the files to splunk and chmod them to 755

the I restart splunk (service splunk stop; service splunk start)

when i log into the web interface and click the Cisco Security App icon, I get a page with 3 javascript alert popups: Splunk encountered the following unknown module: "ConvertToDrilldownSearch" . The view may not load properly.

as well, in red, at the top of the screen is: Misconfigured view 'gc_overview' - Unknown parameter 'drilldown' is defined for module SimpleResultsTable. Make sure the parameter is specified in SimpleResultsTable.conf.

ideas?

Tags (2)
1 Solution

Influencer

Drilldown is a feature that was introduced in Splunk 4.1. Seems like the Cisco Security app uses this features in some views and hence is not compatible with 4.0.x. Your best bet is to upgrade your Splunk installation.

View solution in original post

Influencer

Drilldown is a feature that was introduced in Splunk 4.1. Seems like the Cisco Security app uses this features in some views and hence is not compatible with 4.0.x. Your best bet is to upgrade your Splunk installation.

View solution in original post