Splunk Enterprise Security

Issue with Identity Management lookup expansion with ESS v 3.0 and Splunk 6.0.1 on Windows Platforms

dshakespeare_sp
Splunk Employee
Splunk Employee

Customers running Splunk ESS 3.0 / Splunk 6.0.1 on Windows platforms may experience issues with lookup expansions/creation not working correctly in Identity Management.

There may also be further problems with the Asset/Identity Investigators dashboard eg Asset/identity information is displayed in the upper part of the screen, but the swim lanes at the bottom just show a constant stream of progress dots which never complete.

1 Solution

dshakespeare_sp
Splunk Employee
Splunk Employee

There are known issues with the Windows version of ESS 3.0 with Splunk 6.0.1 (SOLNESS-4642)
These issues are resolved with a new version of "writers.py" and upgrading Splunk to version 6.0.2

If you are experiencing issues Identity Management expansion on Windows and require the new "writers.py"please raise a support ticket with Splunk support quoting this Splunk Answer.

The new file will be included in Splunk For Enterprise Security 3.0.1 and "upgrade" safe

View solution in original post

dshakespeare_sp
Splunk Employee
Splunk Employee

There are known issues with the Windows version of ESS 3.0 with Splunk 6.0.1 (SOLNESS-4642)
These issues are resolved with a new version of "writers.py" and upgrading Splunk to version 6.0.2

If you are experiencing issues Identity Management expansion on Windows and require the new "writers.py"please raise a support ticket with Splunk support quoting this Splunk Answer.

The new file will be included in Splunk For Enterprise Security 3.0.1 and "upgrade" safe

Get Updates on the Splunk Community!

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...

AppDynamics is now part of Splunk Ideas

Hello Splunkers, We have exciting news for you! AppDynamics has been added to the Splunk Ideas Portal. Which ...

Advanced Splunk Data Management Strategies

Join us on Wednesday, May 14, 2025, at 11 AM PDT / 2 PM EDT for an exclusive Tech Talk that delves into ...