Getting Data In

Why is the "connection_host" option in a UDP stanza of inputs.conf being reported as a typo?

hexx
Splunk Employee
Splunk Employee

After an upgrade to 4.2, when Splunk starts up the configuration file checker reports that the "connection_host" option in UDP stanzas of inputs.conf may be a typo :


Checking conf files for typos...
Possible typo in stanza [udp://514] in /opt/splunk/etc/apps/search/local/inputs.conf, line 2: connection_host = ip

This option is perfectly functional and this error is therefore not accurate.

Why is this being reported?

Tags (2)
1 Solution

hexx
Splunk Employee
Splunk Employee

The typo for the "connection_host" configuration parameter in [udp://] stanzas of inputs.conf is indeed misreported and we currently have a bug opened to fix this problem (SPL-38051). This will be fixed in version 4.2.1

If you require an immediate work-around, simply add the following line to $SPLUNK_HOME/etc/system/README/inputs.conf.spec at line 432, under the options defined for [udp://] stanzas :

connection_host = [ip|dns|none]

This will prevent any further false positives on "connection_host".

If you want to know more about how keys in configuration files are checked in 4.2, take a look at this Splunk Answer.

View solution in original post

hexx
Splunk Employee
Splunk Employee

The typo for the "connection_host" configuration parameter in [udp://] stanzas of inputs.conf is indeed misreported and we currently have a bug opened to fix this problem (SPL-38051). This will be fixed in version 4.2.1

If you require an immediate work-around, simply add the following line to $SPLUNK_HOME/etc/system/README/inputs.conf.spec at line 432, under the options defined for [udp://] stanzas :

connection_host = [ip|dns|none]

This will prevent any further false positives on "connection_host".

If you want to know more about how keys in configuration files are checked in 4.2, take a look at this Splunk Answer.

Get Updates on the Splunk Community!

Infographic provides the TL;DR for the 2024 Splunk Career Impact Report

We’ve been buzzing with excitement about the recent validation of Splunk Education! The 2024 Splunk Career ...

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...