Splunk Enterprise Security

How do I suppress possible typo in web.conf for ESS on 4.2

hazekamp
Builder

When I start my Splunk server I see

Possible typo in stanza [settings] in $SPLUNK_HOME/etc/apps/SplunkEnterpriseSecuritySuite/default/web.conf, line: 2: disabled_decomposers = addtermgt, addtermlt

Is this a configuration error? How can I suppress this message?

1 Solution

hazekamp
Builder

This is not a configuration error, rather a setting that has been deprecated in 4.2. In 4.1.5+ one was able to selectively disable decomposers; however in 4.2 decomposition is selectively enabled via the "enable_decomposers" setting.

This message can and should be suppressed (and will be for 4.2.x only compatible builds of ESS):

To suppress, comment (prepend a '#' to) the following line in $SPLUNK_HOME/etc/apps/SplunkEnterpriseSecuritySuite/default/web.conf

Was:

disabled_decomposers = addtermgt, addtermlt

Should be:

#disabled_decomposers = addtermgt, addtermlt

Typically we do not advocate changing "default" configuration files; however, since this is a deprecated setting it cannot be overridden as it should not exist in the first place.

View solution in original post

hazekamp
Builder

This is not a configuration error, rather a setting that has been deprecated in 4.2. In 4.1.5+ one was able to selectively disable decomposers; however in 4.2 decomposition is selectively enabled via the "enable_decomposers" setting.

This message can and should be suppressed (and will be for 4.2.x only compatible builds of ESS):

To suppress, comment (prepend a '#' to) the following line in $SPLUNK_HOME/etc/apps/SplunkEnterpriseSecuritySuite/default/web.conf

Was:

disabled_decomposers = addtermgt, addtermlt

Should be:

#disabled_decomposers = addtermgt, addtermlt

Typically we do not advocate changing "default" configuration files; however, since this is a deprecated setting it cannot be overridden as it should not exist in the first place.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...