Splunk Enterprise

invalid stanza within default stanza [setup] - securegateway.conf

SK3
Engager

I am getting below error on HFs 

Invalid key in stanza [setup] in "/opt/splunk/etc/apps/splunk_secure_gateway/default/securegateway.conf", line 20: cluster_mode_enabled (value: false).

Can anybody tell us why?

Labels (2)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Fisrtly, https://docs.splunk.com/Documentation/SecureGateway/3.5.15/Admin/ConfigureSecureGatewayConf

"In Splunk Secure Gateway version 3.4.25 and higher, Splunk Secure Gateway no longer reads from the securegateway.conf file. Configure Secure Gateway using the UI in Administration > Deployment configuration > Advanced settings"

Secondly, you should not need SSG on HFs.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...