Splunk Enterprise Security

Incident Review and Investigations page errored out after ESS 5.3.0 upgrade

jawaharas
Motivator

After upgrading 'Splunk Enterprise Security' from version 5.1.0 to 5.3.0, 'Incident Review', and Investigations page errored out with below errors.

  1. Incident Review:
    URL: https://domain_name/en-US/app/SplunkEnterpriseSecuritySuite/incident_review
    Error Message: Unable to xml-parse the following data: %s

  2. Investigations:
    URL: https://domain_name/en-US/app/SplunkEnterpriseSecuritySuite/ess_investigation_list
    Error Message: JSON.parse: unexpected character at line 1 column 1 of the JSON data

Any help is welcome one. Thanks.

0 Karma
1 Solution

Splunker
Communicator

Try the fix for SOLNESS-18773

https://docs.splunk.com/Documentation/ES/5.3.0/RN/KnownIssues

Assuming it's ES on Windows. If that doesn't fix it, suggest contacting support (and advising the fix here too would be nice) 🙂

Cheers,

Chris.

View solution in original post

0 Karma

Splunker
Communicator

Try the fix for SOLNESS-18773

https://docs.splunk.com/Documentation/ES/5.3.0/RN/KnownIssues

Assuming it's ES on Windows. If that doesn't fix it, suggest contacting support (and advising the fix here too would be nice) 🙂

Cheers,

Chris.

0 Karma

jawaharas
Motivator

After replacing the python script (log.py) provided by Splunk support, the issue is fixed and it works for Linux environment as well.

1. Stop Splunk.

2. Take backup of the following two files. (e.g. log.py.bak)

$SPLUNK_HOME\etc\apps\SA-Utils\lib\SolnCommon\log.py
$SPLUNK_HOME\etc\apps\SplunkEnterpriseSecuritySuite\lib\SplunkEnterpriseSecuritySuite\log.py

3. Replace the following two files with the attached modified log.py file. (Rename the file extension to ".py" before replacing.)

$SPLUNK_HOME\etc\apps\SA-Utils\lib\SolnCommon\log.py
$SPLUNK_HOME\etc\apps\SplunkEnterpriseSecuritySuite\lib\SplunkEnterpriseSecuritySuite\log.py

4. Start Splunk again.
0 Karma

Splunker
Communicator

Awesome, this will help many people. Thanks!

Chris.

0 Karma

mdennis0177
New Member

I don't see the attached py file....

0 Karma

sloshburch
Splunk Employee
Splunk Employee

I think you have to get it from support.

0 Karma

jawaharas
Motivator

Thanks Chris. I ve submitted case with Splunk support and will let you know the outcome of the fix.

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...