Splunk Enterprise Security

Splunk ES - lookup_expander - assets.csv - not handling IPv6?

OL
Communicator

Hello Splunk ES users 🙂

I'm using the latest Splunk ES (2.4.0) and since the upgrade from 2.0.2, I have the following error:

lookup_expander: Some lines in the input CSV contained bad data (file: /opt/splunk/etc/apps/SA-IdentityManagement/lookups/assets.csv, count: 141)

All 141 errors are coming from the entries which are using IPv6 from the assets.csv. Isn't ES support IPv6?

Regards,
Olivier

1 Solution

LukeMurphey
Champion

Sadly, ES doesn't support IPv6, yet.

View solution in original post

LukeMurphey
Champion

Sadly, ES doesn't support IPv6, yet.

Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...