Splunk Enterprise Security

Splunk Enterprise Security: Unable to save Input stanza for lookup source

prammod123
Explorer

We are implementing the Splunk ES in our environment, when I try to save input stanza for lookup source under Configure > Data Enrichment > Identity Management, I receive an error "Encountered the following error while trying to save: The following required arguments are missing: master_host."

Any references are much appreciated.

0 Karma

lakshman239
Influencer

Under Configure > Data Enrichment > Identity Management, are you trying to update an existing definition (i.e 'Name') or adding your own? Did you try to change/update the config from back-end ?(SA-IdentityManagement/local)

0 Karma

prammod123
Explorer

BTW, I see master_host attirbute of SA-IdentityManagement addon inputs.conf has not been set and not sure what value to set for the attribute master_host

0 Karma

prammod123
Explorer

I am trying to create a new definition

0 Karma
Get Updates on the Splunk Community!

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Seamless IT/OT Security: A Hands-On Look at the Cisco Cyber Vision Splunk Add-on

With just a few clicks, you can ingest critical OT asset details, vulnerabilities, baseline deviations, ...

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...