Hi To All Splunkers,
I'm having problem on getting the data from McAfee epo to my splunk indexer server.
previously this was working, it so happened one day it stop capturing the data.
Below is the error message I found from the splunk log:
09-22-2012 00:42:34.868 +0800 ERROR ExecProcessor - message from ""D:\Program Files\Splunk\etc\apps\TA-mcafee\bin\mcafee_epo.bat"" 'import site' failed; use -v for traceback
09-22-2012 00:42:34.868 +0800 ERROR ExecProcessor - message from ""D:\Program Files\Splunk\etc\apps\TA-mcafee\bin\mcafee_epo.bat"" Traceback (most recent call last):
09-22-2012 00:42:34.868 +0800 ERROR ExecProcessor - message from ""D:\Program Files\Splunk\etc\apps\TA-mcafee\bin\mcafee_epo.bat"" File "D:\Program Files\Splunk\etc\apps\TA-mcafee\bin\mcafee_epo.py", line 2, in <module>
09-22-2012 00:42:34.868 +0800 ERROR ExecProcessor - message from ""D:\Program Files\Splunk\etc\apps\TA-mcafee\bin\mcafee_epo.bat"" import pymssql
09-22-2012 00:42:34.868 +0800 ERROR ExecProcessor - message from ""D:\Program Files\Splunk\etc\apps\TA-mcafee\bin\mcafee_epo.bat"" ImportError: No module named pymssql
09-22-2012 00:42:34.868 +0800 INFO ExecProcessor - Ran script: "D:\Program Files\Splunk\etc\apps\TA-mcafee\bin\mcafee_epo.bat", took 190.0 milliseconds to run, 0 bytes read, exited with code 1
Thanks in advanced for the help.
... View more