Splunk Enterprise Security

Splunk Enterprise Security and Splunk 6.5.2: When clicking "Event Actions" button within an expanded event, why do I receive "TypeError: message is undefined" error?

mhoogenboom
New Member

Since upgrading Splunk to 6.5.2, in the Splunk Enterprise Security (ES) search page I get "TypeError: message is undefined" when clicking the "Event Actions" button within an expanded event. The same thing happens on the "Incident Review" page if I click the down arrow in any column of the events table. This happens in both Firefox and Internet Explorer (IE) 11

TypeError: message is undefined

_()
 i18n.js:30
["require/underscore"]/__WEBPACK_AMD_DEFINE_RESULT__</<.t()
 common.js:175
["contrib/underscore"]/</_.mixin/</_.prototype[name]()
 common.js:178
anonymous()
 common.js line 178 > Function:22
["contrib/underscore"]/</_.template/template()
 common.js:178
["views/shared/eventsviewer/shared/WorkflowActions"]/__WEBPACK_AMD_DEFINE_RESULT__</<.render()
 common.js:240
["views/Base"]/__WEBPACK_AMD_DEFINE_RESULT__
0 Karma

mhoogenboom
New Member

This is resolved. The error was caused by a corrupted file: in $SPLUNK_HOME/etc/apps/SA-ThreatIntelligence/local/workflow_actions.conf

I deleted this file, restarted splunk and no more errors.

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

Thanks for the update!

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

What version of Splunk Enterprise Security do you have installed? Have you cleared your browser cache?

0 Karma

mhoogenboom
New Member

Hi, it's 4.5.2 and yes I have tried clearing my browser cache. This issue is affecting all users of our ES app.

Thanks.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...