Splunk Enterprise Security

Splunk Enterprise Security and Splunk 6.5.2: When clicking "Event Actions" button within an expanded event, why do I receive "TypeError: message is undefined" error?

mhoogenboom
New Member

Since upgrading Splunk to 6.5.2, in the Splunk Enterprise Security (ES) search page I get "TypeError: message is undefined" when clicking the "Event Actions" button within an expanded event. The same thing happens on the "Incident Review" page if I click the down arrow in any column of the events table. This happens in both Firefox and Internet Explorer (IE) 11

TypeError: message is undefined

_()
 i18n.js:30
["require/underscore"]/__WEBPACK_AMD_DEFINE_RESULT__</<.t()
 common.js:175
["contrib/underscore"]/</_.mixin/</_.prototype[name]()
 common.js:178
anonymous()
 common.js line 178 > Function:22
["contrib/underscore"]/</_.template/template()
 common.js:178
["views/shared/eventsviewer/shared/WorkflowActions"]/__WEBPACK_AMD_DEFINE_RESULT__</<.render()
 common.js:240
["views/Base"]/__WEBPACK_AMD_DEFINE_RESULT__
0 Karma

mhoogenboom
New Member

This is resolved. The error was caused by a corrupted file: in $SPLUNK_HOME/etc/apps/SA-ThreatIntelligence/local/workflow_actions.conf

I deleted this file, restarted splunk and no more errors.

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

Thanks for the update!

0 Karma

smoir_splunk
Splunk Employee
Splunk Employee

What version of Splunk Enterprise Security do you have installed? Have you cleared your browser cache?

0 Karma

mhoogenboom
New Member

Hi, it's 4.5.2 and yes I have tried clearing my browser cache. This issue is affecting all users of our ES app.

Thanks.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...