I am getting the following in our Splice logs
05-21-2015 11:10:57.421 -0700 ERROR ExecProcessor - message from "python "C:\Program Files\Splunk\etc\apps\SA-Splice\bin\taxii.py"" '\xef\xbb\xbf\n'
05-21-2015 11:10:56.919 -0700 ERROR ExecProcessor - message from "python "C:\Program Files\Splunk\etc\apps\SA-Splice\bin\taxii.py"" file: C:\Program Files\Splunk\etc\apps\SA-Splice\local\splice.conf, line: 1
05-21-2015 11:10:56.919 -0700 ERROR ExecProcessor - message from "python "C:\Program Files\Splunk\etc\apps\SA-Splice\bin\taxii.py"" ERRORFile contains no section headers.
I have MongoDB configured, and I can connect remotely using mongo.exe without credentials. I created the database "SPLICE" and I have the Splice app configured as such: mongodb://localhost:27017/SPLICE (mongodb is running on my Splunk server).
The IOC feed I am trying to connect to is the built-in "hailataxii" feed.
Does anyone have the first clue about these errors? Is this because I am running Splice in a Splunk Windows environment?
... View more