Splunk Enterprise Security

Splunk Enterprise Security and Splunk 6.5.2: When clicking "Event Actions" button within an expanded event, why do I receive "TypeError: message is undefined" error?

mhoogenboom
New Member

Since upgrading Splunk to 6.5.2, in the Splunk Enterprise Security (ES) search page I get "TypeError: message is undefined" when clicking the "Event Actions" button within an expanded event. The same thing happens on the "Incident Review" page if I click the down arrow in any column of the events table. This happens in both Firefox and Internet Explorer (IE) 11

TypeError: message is undefined

_()
 i18n.js:30
["require/underscore"]/__WEBPACK_AMD_DEFINE_RESULT__</<.t()
 common.js:175
["contrib/underscore"]/</_.mixin/</_.prototype[name]()
 common.js:178
anonymous()
 common.js line 178 > Function:22
["contrib/underscore"]/</_.template/template()
 common.js:178
["views/shared/eventsviewer/shared/WorkflowActions"]/__WEBPACK_AMD_DEFINE_RESULT__</<.render()
 common.js:240
["views/Base"]/__WEBPACK_AMD_DEFINE_RESULT__
0 Karma

mhoogenboom
New Member

This is resolved. The error was caused by a corrupted file: in $SPLUNK_HOME/etc/apps/SA-ThreatIntelligence/local/workflow_actions.conf

I deleted this file, restarted splunk and no more errors.

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

Thanks for the update!

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

What version of Splunk Enterprise Security do you have installed? Have you cleared your browser cache?

0 Karma

mhoogenboom
New Member

Hi, it's 4.5.2 and yes I have tried clearing my browser cache. This issue is affecting all users of our ES app.

Thanks.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...