Monitoring Splunk

btool app name length limit

YisroelB
Explorer

It looks as if btool, when run with --debug, only shows the first 10 characters of the app name. Unfortunately the first 10 characters of of our app names are often the same.

Is there any way around this? ...and please don't say rename all your apps 🙂

Thanks,

-Yisroel

Tags (2)
1 Solution

sowings
Splunk Employee
Splunk Employee

This issue has been fixed as of version 5.0.3. That version shows the full path to the file that contains the "winning" setting. With versions prior to that, you'll have to resort to find with -exec grep {} \; or some other (admittedly painful) means.

View solution in original post

sowings
Splunk Employee
Splunk Employee

This issue has been fixed as of version 5.0.3. That version shows the full path to the file that contains the "winning" setting. With versions prior to that, you'll have to resort to find with -exec grep {} \; or some other (admittedly painful) means.

hexx
Splunk Employee
Splunk Employee

I would discourage you from trying to do so. It's very likely not to work as I believe that btool relies on the splunkd binary to do some of its work.

0 Karma

sowings
Splunk Employee
Splunk Employee

Fair question. I suppose the answer is found in the response to "does your local system have the shared libraries required by the new btool program?" You could copy a 5.0.3 btool binary to your system into say your home directory, and try 'ldd btool' to see if it can find the libraries it needs.

0 Karma

YisroelB
Explorer

Thanks. Can I use the updated btool with 4.3.6?

0 Karma

YisroelB
Explorer

Can I get a fix? Should I open a case?

0 Karma

Lucas_K
Motivator

We actually noticed this just recently also. Ironically it is a bug with the debug output.

0 Karma
Get Updates on the Splunk Community!

See Splunk Platform & Observability Innovations at Cisco Live EMEA

Hi Splunkers, Learn about what’s next for Splunk Platform at Cisco Live EMEA.  Data silos are a big challenge ...

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...