All Apps and Add-ons

Can't configure TA-symantec_atp v1.5.0

florin
Observer

Hi, 
I'm trying to configure TA-symantec_atp v1.5.0 on Splunk 8.1.6 version of splunk but nothing happens when I try to save the config in UI page. 


I found below errors in "/opt/splunk/var/log/splunk/python.log":

2021-09-22 13:18:41,150 +0200 ERROR __init__:164 - The REST handler module "email_symantec_util" could not be found. Python files must be in $SPLUNK_HOME/etc/apps/$MY_APP/bin/
2021-09-22 13:18:41,150 ERROR The REST handler module "email_symantec_util" could not be found. Python files must be in $SPLUNK_HOME/etc/apps/$MY_APP/bin/
2021-09-22 13:18:41,151 +0200 ERROR __init__:165 - No module named 'rapid_diag'
Traceback (most recent call last):
File "/opt/splunk/lib/python3.7/site-packages/splunk/rest/__init__.py", line 161, in dispatch
module = __import__('splunk.rest.external.%s' % parts[0], None, None, parts[0])
File "/opt/splunk/etc/apps/TA-symantec_atp/bin/email_symantec_util.py", line 6, in <module>
from . import logger_manager
File "/opt/splunk/etc/apps/splunk_rapid_diag/bin/logger_manager.py", line 14, in <module>
from rapid_diag.util import get_splunkhome_path, get_app_conf
ModuleNotFoundError: No module named 'rapid_diag'

And "/opt/splunk/var/log/splunk/web_service.log":

2021-09-22 13:24:03,700 ERROR [614b1253af7ff740791c10] utility:58 - name=javascript, class=Splunk.Error, lineNumber=272, message=Uncaught TypeError: Cannot read properties of undefined (reading 'data'), fileName=https://localhost:8443/en-US/static/@071D8440E5D1A785ECFF180D1ECF4589ACA117B332BB46A44AF934EFD3BCE24...
2021-09-22 13:24:05,706 ERROR [614b1255af7ff75b72bcd0] utility:58 - name=javascript, class=Splunk.Error, lineNumber=272, message=Uncaught TypeError: Cannot read properties of undefined (reading 'data'), fileName=https://localhost:8443/en-US/static/@071D8440E5D1A785ECFF180D1ECF4589ACA117B332BB46A44AF934EFD3BCE24...
2021-09-22 13:24:07,698 ERROR [614b1257ad7ff740411e50] utility:58 - name=javascript, class=Splunk.Error, lineNumber=272, message=Uncaught TypeError: Cannot read properties of undefined (reading 'data'), fileName=https://localhost:8443/en-US/static/@071D8440E5D1A785ECFF180D1ECF4589ACA117B332BB46A44AF934EFD3BCE24...
2021-09-22 13:24:09,702 ERROR [614b1259ae7ff740791790] utility:58 - name=javascript, class=Splunk.Error, lineNumber=272, message=Uncaught TypeError: Cannot read properties of undefined (reading 'data'), fileName=https://localhost:8443/en-US/static/@071D8440E5D1A785ECFF180D1ECF4589ACA117B332BB46A44AF934EFD3BCE24...

Background:
I'm currently using TA-symantec_atp v1.3.0 with Splunk 7.3.2 but I want to upgrade to Splunk 8.1.X and only TA-symantec_atp v1.5.0 is compatible with 8.1.x and above (python 3)

I've tried to install and configure v1.5.0 of the addon on several machines running Splunk 8.1.x but all resulted in same error described above. 

Does anybody had this TA working? 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Combine Multiline Logs into a Single Event with SOCK - a Guide for Advanced Users

This article is the continuation of the “Combine multiline logs into a single event with SOCK - a step-by-step ...

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...