All Apps and Add-ons

Why is the Windows TA broken out of the box?

merch_sf
Engager

I just installed the Windows TA.  Now, when I search, I get the following errors:

  • Could not load lookup=LOOKUP-action_for_win_timesync_status
  • Could not load lookup=LOOKUP-app4_for_windows_security
  • Could not load lookup=LOOKUP-app_for_windows_system_ias
  • Could not load lookup=LOOKUP-vendor_info_for_microsoft_dhcp
  • Could not load lookup=LOOKUP-vendor_info_for_windows_security
  • Could not load lookup=LOOKUP-vendor_info_for_windows_system
  • Could not load lookup=LOOKUP-vendor_info_for_windowsupdatelog

These are all automated lookups in props.conf.  The lookups don't exist.  There are no saved searches in the TA that would create them.

How is it possible that the Windows TA (and Linux TA for that matter), which are two of the most downloaded apps in the Splunkbase, are so broken?  I can't believe your company can find the time to build useless apps for the Apple Watch, but you can't nail the two most widely utilized apps for getting data into Splunk.

Shame on you.

Tags (1)

sathwik067
Explorer

Hi, 

 

Can you please let me know if you find any solution for this? I am still not able to figure out this errors. 

0 Karma

kamlesh_vaghela
SplunkTrust
SplunkTrust

@merch_sf 

 

Can you please share Windows TA version and Splunk Version ?

0 Karma
Get Updates on the Splunk Community!

Everything Community at .conf24!

You may have seen mention of the .conf Community Zone 'round these parts and found yourself wondering what ...

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...