All Apps and Add-ons

Error while posting to url=/servicesNS/nobody/Splunk_CiscoSecuritySuite/css_setup/css_setup_endpoint/default

sec_team_albara
New Member

Cisco security suite application installed on splunk entreprise 7.2.3 (windows platfrom).
When trying to configure the application by checking "Enable Cisco ASA Dashboards ", I receive the following error:
Error while posting to url=/servicesNS/nobody/Splunk_CiscoSecuritySuite/css_setup/css_setup_endpoint/default

I modified $SPLUNK_HOME/etc/apps/Splunk_CiscoSecuritySuite/local/app.conf
[install]
is_configured = 1
Unfortunately, I still receive the same issue.

Your help is much appreciated

0 Karma

antlefebvre
Communicator

Not sure if this will work/apply for you. I did this with success on a ubuntu install (not windows) and entered true rather than 1. Splunk 7.2.5.

To do so, open etc/apps/Splunk_CiscoSecuriySuite/local/app.conf (or create it if it does not exist) and enter the following:

[install]
is_configured = true

You may need to restart Splunk after editing the config file. Splunk won't force you to view the setup screen once it recognizes the app is considered configured.

Original post here: https://answers.splunk.com/answers/12702/splunk-cisco-security-suite.html

0 Karma

lino_76
New Member

Following up from my previous post.

In effort move forward and save time, I decided to uninstall Splunk Version 7.2.3 and install (at random) Splunk version 6.5.2. I now can see Cisco Security Suite and installed it successfully without an errors.
Not sure if the app works beyond version 6.5.2 or before 7.2.3.

Hope this helps...

0 Karma

lino_76
New Member

I'm seeing the same error with my version of Splunk (version 7.3). Is there a solution for this error?

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...