Splunk Enterprise Security

Issue with Identity Management lookup expansion with ESS v 3.0 and Splunk 6.0.1 on Windows Platforms

dshakespeare_sp
Splunk Employee
Splunk Employee

Customers running Splunk ESS 3.0 / Splunk 6.0.1 on Windows platforms may experience issues with lookup expansions/creation not working correctly in Identity Management.

There may also be further problems with the Asset/Identity Investigators dashboard eg Asset/identity information is displayed in the upper part of the screen, but the swim lanes at the bottom just show a constant stream of progress dots which never complete.

1 Solution

dshakespeare_sp
Splunk Employee
Splunk Employee

There are known issues with the Windows version of ESS 3.0 with Splunk 6.0.1 (SOLNESS-4642)
These issues are resolved with a new version of "writers.py" and upgrading Splunk to version 6.0.2

If you are experiencing issues Identity Management expansion on Windows and require the new "writers.py"please raise a support ticket with Splunk support quoting this Splunk Answer.

The new file will be included in Splunk For Enterprise Security 3.0.1 and "upgrade" safe

View solution in original post

dshakespeare_sp
Splunk Employee
Splunk Employee

There are known issues with the Windows version of ESS 3.0 with Splunk 6.0.1 (SOLNESS-4642)
These issues are resolved with a new version of "writers.py" and upgrading Splunk to version 6.0.2

If you are experiencing issues Identity Management expansion on Windows and require the new "writers.py"please raise a support ticket with Splunk support quoting this Splunk Answer.

The new file will be included in Splunk For Enterprise Security 3.0.1 and "upgrade" safe

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...