Yes. I got the fix from the App owner as I was working with him at .conf2012 earlier today. He will update the code later on tonight to the repository. Should be version 2.0.2 or up.
But to get your Splunk or search head working until the fix is ready, you have to go to find the indexer.conf file in the FireEye App and do the configuration change below to start the splunk again.
/opt/splunk/etc/apps/{FireEye, or SplunkforFireEye}/default
more indexes.conf
[fireeye]
for syslog data
coldPath = $SPLUNK_DB/fireeye/colddb
homePath = $SPLUNK_DB/fireeye/db
thawedPath = $SPLUNK_DB/fireeye/thaweddb
[fe]
for xml fireeye logs
coldPath = $SPLUNK_DB/fireeye/colddb
homePath = $SPLUNK_DB/fireeye/db
thawedPath = $SPLUNK_DB/fireeye/thaweddb
[fe]
for xml fireeye logs
coldPath = $SPLUNK_DB/fe/colddb
homePath = $SPLUNK_DB/fe/db
thawedPath = $SPLUNK_DB/fe/thaweddb
Hope this help.
... View more