Splunk Enterprise

Hunting an APT with Splunk - Reconnaissance

lorraine
Loves-to-Learn Lots

Hello!
I am new to Splunk and attempting the BOTS workshop, Hunting an APT with Splunk - Reconnaissance, and have encountered an issue.
Following the video, I tried to access the identity centre, asset centre and the Frothly environment network diagram.
However none of these are working for me.
The Frothly environment shows a blank screen.
The Identity and Asset centres show an error in 'inputlookup' command: External command based lookup 'identity_lookup_expanded is not available because KV store initialisation has failed.
Does anyone have any idea how to get around this, or has anyone else encountered this error?

Labels (1)
0 Karma

kprior201
Path Finder

If the KVStore initialization has failed, you'll definitely have a lot of issues. You'll need to figure out why that is by looking through $SPLUNK_HOME/var/log/splunk/mongod.log to see what's going on there and address it first.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...