We recently updated our Splunkadd-onforWindows to 5.0.1, whenever searching we receive the error "Could not load lookup=LOOKUP-app4_for_windows_security" from all of our indexers and search head....
TheSplunk App forWindows Infrastructure releasenotesfor 1.5.2 are completely blank.
Is there any other way of figuring out what changes were made without having to do a file comparison?
...' for conf 'source::XmlWinEventLog:Security' and lookup table 'windows_app_lookup'.
This happens in all the searches I do in splunk. What can it be?
Is it possible to pull in Data from Apache Tomcat servers into Splunk that's sitting on a windows box?
I believe the answer is yes but wanted confirmation.
thank you
PS: i understand this i...
After the install and configuration of IMAP Mailbox app, it's not indexing any email. I was successful at getting this working in our lab environment, but not our production splunk environment.
Splunk...
snow_incident.py is no longer able to run after updating to add-on version 5.0. It cannot actually find the configured account in theadd-on. Has anyone run into this issue?
2019-11-20 08:20:1...
After upgrading to SplunkAdd-onfor Microsoft Windows 5.0.0 and Splunk App forWindows Infrastructure 1.4.4 it seems I get the following errors ever query I put in:
Error 'Could not find all of the...