Monitoring Splunk

How to fix aggregration issue for sourcetype

AL3Z
Builder

Hi,

I have seen a aggregration issue for one of my source type cisco, how can I fix this issue  in my splunk cloud ?

12-06-2023 17:42:27.004 +0000 ERROR AggregatorMiningProcessor [82698 merging_0] - Uncaught exception in Aggregator, skipping an event: Can't open DateParser XML configuration file "/opt/splunk/etc/peer-apps/Splunk_TA_cisco-ise/default/datetime_udp.xml": No such file or directory - data_source="/syslog/nac/ise.log", data_host="ise-xx", data_sourcetype="cisco:ise:syslog"

Thanks...

 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The datetime_udp.xml file doesn't exist on the indexer(s).  Double-check the add-on.  Consider re-installing it.  If it's still a problem, contact Splunk Cloud support or the add-on vendor.

---
If this reply helps you, Karma would be appreciated.
0 Karma

AL3Z
Builder

@richgalloway 

Hi,

From below mentioned post they fixed this by creating a local/props.conf 
https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-ISE-TA-fails-when-distributed-via-Cluste...

props.conf

[cisco:ise]
DATETIME_CONFIG = /etc/slave-apps/Splunk_TA_cisco-ise/default/datetime_udp.xml

[cisco:ise:syslog]
DATETIME_CONFIG = /etc/slave-apps/Splunk_TA_cisco-ise/default/datetime_udp.xml

How we can create this in the splunk cloud is it possible from all configurations ??

Thanks in advance.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Add the props.conf file to an app and upload the app to Splunk Cloud.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...