Splunk Enterprise Security

Metrics definition errors in the add-on - is fix available in future version?

lakshman239
SplunkTrust
SplunkTrust

The latest add-on 4.6.0 installed on splunk 7.1.3, when restarted throws an the following error: Any plans to fix them sooner?

            Invalid key in stanza [aws:cloudwatch:metric] in /opt/splunk/etc/apps/Splunk_TA_aws/default/props.conf, line 242: METRIC-SCHEMA-TRANSFORMS  (value:  metric-schema:aws_cloudwatch_metric_schema).

            Invalid key in stanza [eval_aws_metric_name_prefix] in /opt/splunk/etc/apps/Splunk_TA_aws/default/transforms.conf, line 75: INGEST_EVAL  (value:  metric_name = Namespace.".".MetricName).

            Invalid key in stanza [metric-schema:aws_cloudwatch_metric_schema] in /opt/splunk/etc/apps/Splunk_TA_aws/default/transforms.conf, line 78: METRIC-SCHEMA-MEASURES  (value:  SampleCount,Average,Sum,Minimum,Maximum).

            Your indexes and inputs configurations are not internally consistent. For more information, run 'splunk btool check –debug
0 Karma
1 Solution

lakshman239
SplunkTrust
SplunkTrust

Adding the below as its now available in release notes as Known Issue - ADDON-19138 and will be supported from Splunk 7.2+

View solution in original post

lakshman239
SplunkTrust
SplunkTrust

Adding the below as its now available in release notes as Known Issue - ADDON-19138 and will be supported from Splunk 7.2+

Get Updates on the Splunk Community!

Using Machine Learning for Hunting Security Threats

WATCH NOW Seeing the exponential hike in global cyber threat spectrum, organizations are now striving more for ...

New Learning Videos on Topics Most Requested by You! Plus This Month’s New Splunk ...

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

How I Instrumented a Rust Application Without Knowing Rust

As a technical writer, I often have to edit or create code snippets for Splunk's distributions of ...