Splunk Enterprise Security

Splunk Enterprise Security: Unable to save Input stanza for lookup source

prammod123
Explorer

We are implementing the Splunk ES in our environment, when I try to save input stanza for lookup source under Configure > Data Enrichment > Identity Management, I receive an error "Encountered the following error while trying to save: The following required arguments are missing: master_host."

Any references are much appreciated.

0 Karma

lakshman239
Influencer

Under Configure > Data Enrichment > Identity Management, are you trying to update an existing definition (i.e 'Name') or adding your own? Did you try to change/update the config from back-end ?(SA-IdentityManagement/local)

0 Karma

prammod123
Explorer

BTW, I see master_host attirbute of SA-IdentityManagement addon inputs.conf has not been set and not sure what value to set for the attribute master_host

0 Karma

prammod123
Explorer

I am trying to create a new definition

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...