ModularInputs Errors After Upgrading to Splunk App 2.0 or 2.1
search cancel

ModularInputs Errors After Upgrading to Splunk App 2.0 or 2.1

book

Article ID: 291253

calendar_today

Updated On:

Products

Carbon Black Cloud Endpoint Standard (formerly Cb Defense) Carbon Black Cloud Enterprise EDR (formerly Cb Threathunter)

Issue/Introduction

  • After upgrading the CBC Splunk App it starts erroring
  • Seeing "ERROR ModuleInputs" and "SyntaxError: invalid syntax" errors 

Environment

  • Carbon Black Cloud: All Supported Versions
  • Splunk App: 2.0.0 and 2.1.0

Cause

Known issue in EA-24507 which is resolved in Splunk App 2.2.1

Resolution

Upgrade to the Carbon Black Cloud Splunk App 2.2.1 or Higher

Additional Information

To gather logs please follow the directions here