Splunk Enterprise Security

Getting an error after degrading Splunk enterprise security.

Inayath_khan
Path Finder

Unable to initialize modular input "whois" defined in the app "SA-NetworkProtection": Introspecting scheme=whois: script running failed (exited with code 1)

Also while opening content management windows : Getting Could not load analytical stories

Kindly suggest!!

0 Karma

Morizard
New Member

Hi
I Have this problem too
my splunk version is 10.0.0
and my ES version 8.1.1
and i have
one search head 
one masternode
two indexer
one heavy forwarder
and i have this problem in my indexer



/opt/splunk/bin/splunk cmd python /opt/splunk/etc/peer-apps/SA-NetworkProtection/bin/whois.py --domain=google.com
Traceback (most recent call last):
File "/opt/splunk/etc/peer-apps/SA-NetworkProtection/bin/whois.py", line 14, in <module>
from SolnCommon.modinput import (BooleanField, Field, FieldValidationException,
ModuleNotFoundError: No module named 'SolnCommon'

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...