When using the Splunk Add-on for Google Cloud Platform the input name cannot contain slashes.
"GCP Cloud Pub/Sub Input" <== This will break with the following error.
ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/Splunk_TA_google-cloudplatform/bin/google_cloud_pubsub.py" OSError: [Errno 2] No such file or directory: '/opt/splunk/var/lib/splunk/modinputs/google_cloud_pubsub/GCP Cloud Pub/Sub Input.lock'
Special characters should be disallowed in the input name on that add-on. Additionally, the input name should be properly escaped.
P.S.
Please update the horrible, horrible documentation around how to configure that add-on.
... View more