Monitoring Splunk

How to fix aggregration issue for sourcetype

AL3Z
Builder

Hi,

I have seen a aggregration issue for one of my source type cisco, how can I fix this issue  in my splunk cloud ?

12-06-2023 17:42:27.004 +0000 ERROR AggregatorMiningProcessor [82698 merging_0] - Uncaught exception in Aggregator, skipping an event: Can't open DateParser XML configuration file "/opt/splunk/etc/peer-apps/Splunk_TA_cisco-ise/default/datetime_udp.xml": No such file or directory - data_source="/syslog/nac/ise.log", data_host="ise-xx", data_sourcetype="cisco:ise:syslog"

Thanks...

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The datetime_udp.xml file doesn't exist on the indexer(s).  Double-check the add-on.  Consider re-installing it.  If it's still a problem, contact Splunk Cloud support or the add-on vendor.

---
If this reply helps you, Karma would be appreciated.
0 Karma

AL3Z
Builder

@richgalloway 

Hi,

From below mentioned post they fixed this by creating a local/props.conf 
https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-ISE-TA-fails-when-distributed-via-Cluste...

props.conf

[cisco:ise]
DATETIME_CONFIG = /etc/slave-apps/Splunk_TA_cisco-ise/default/datetime_udp.xml

[cisco:ise:syslog]
DATETIME_CONFIG = /etc/slave-apps/Splunk_TA_cisco-ise/default/datetime_udp.xml

How we can create this in the splunk cloud is it possible from all configurations ??

Thanks in advance.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Add the props.conf file to an app and upload the app to Splunk Cloud.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...