Splunk Enterprise Security

invalid key for param.default_disposition on Splunk ES 6.6.0

joshuahuang1
Engager

I recently installed brand new Splunk 8.2.2, then installed Splunk ES 6.6.0 on it, after Splunk ES installed and configured, I restarted Splunk from CLI, from that I got below error message:

"Checking conf files for problems... Invalid key in stanza [notable] in /opt/splunk/etc/apps/SA-ThreatIntelligence/default/alert_actions.conf, line 84: param.default_disposition (value: )."

 

There is no such error on Splunk ES 6.4.1, and there is also no such key, it's new from ES 6.6.0, who knows how to fix it? many thanks!

Labels (1)
0 Karma

miladalizadeh
Engager
I have This issue help Me Pls
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...