Splunk Enterprise Security

Issue with Identity Management lookup expansion with ESS v 3.0 and Splunk 6.0.1 on Windows Platforms

dshakespeare_sp
Splunk Employee
Splunk Employee

Customers running Splunk ESS 3.0 / Splunk 6.0.1 on Windows platforms may experience issues with lookup expansions/creation not working correctly in Identity Management.

There may also be further problems with the Asset/Identity Investigators dashboard eg Asset/identity information is displayed in the upper part of the screen, but the swim lanes at the bottom just show a constant stream of progress dots which never complete.

1 Solution

dshakespeare_sp
Splunk Employee
Splunk Employee

There are known issues with the Windows version of ESS 3.0 with Splunk 6.0.1 (SOLNESS-4642)
These issues are resolved with a new version of "writers.py" and upgrading Splunk to version 6.0.2

If you are experiencing issues Identity Management expansion on Windows and require the new "writers.py"please raise a support ticket with Splunk support quoting this Splunk Answer.

The new file will be included in Splunk For Enterprise Security 3.0.1 and "upgrade" safe

View solution in original post

dshakespeare_sp
Splunk Employee
Splunk Employee

There are known issues with the Windows version of ESS 3.0 with Splunk 6.0.1 (SOLNESS-4642)
These issues are resolved with a new version of "writers.py" and upgrading Splunk to version 6.0.2

If you are experiencing issues Identity Management expansion on Windows and require the new "writers.py"please raise a support ticket with Splunk support quoting this Splunk Answer.

The new file will be included in Splunk For Enterprise Security 3.0.1 and "upgrade" safe

Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Unleash Unified Security and Observability with Splunk Cloud Platform

     Now Available on Microsoft AzureThursday, March 27, 2025  |  11AM PST / 2PM EST | Register NowStep boldly ...

Splunk AppDynamics with Cisco Secure Application

Web applications unfortunately present a target rich environment for security vulnerabilities and attacks. ...