Splunk® Add-on Builder

Splunk Add-on Builder User Guide

Download manual as PDF

Download topic as PDF

Known issues for Splunk Add-on Builder

This version of Splunk Add-on Builder has the following known issues and workarounds.

Date filed Issue number Description
2017-09-25 TAB-2762 Non-standard characters in other add-on's clear passwords can cause Add-on Builder setup to hang.

Workaround:
Disable the offending TA.
2017-08-07 TAB-2738 Incorrect license agreement packaged in Add-on Builder

Workaround:
See the license linked from the Splunkbase page for the correct licensing information.
2017-06-22 TAB-2693 Renaming add-on and then deleting it causes an internal error.
2017-06-15 TAB-2660 Some characters in sourcetype are not supported by Add-on Builder
2017-06-08 TAB-2631 Alert action not working on Windows if TA path is too long
2017-06-05 TAB-2607 Sourcetype set for data input log file doesn't take effect until restart
2016-11-29 TAB-1736 Error when user installs both Splunk DB Connect and Add-on Builder.
PREVIOUS
What's new
  NEXT
Fixed issues for Splunk Add-on Builder

This documentation applies to the following versions of Splunk® Add-on Builder: 2.2.0


Comments

I've packaged a props.conf which contained several parameters including KV_MODE = none with the Splunk Add-on Builder and when downloading the spl package, I am finding the following parameter removed from the props.conf.
KV_MODE = none

Below is the actual props.conf if you wish to verify the issue.
[custom:json]
DATETIME_CONFIG =
INDEXED_EXTRACTIONS = json
KV_MODE = none
LINE_BREAKER = ([\r\n]+)
NO_BINARY_CHECK = true
TIMESTAMP_FIELDS = timestamp.$date
TIME_FORMAT = %Y-%m-%dT%H:%M:%S.%3N
TZ = UTC
category = Structured
description = JavaScript Object Notation format. For more information, visit http://json.org/
disabled = false

Rob jordan relativity
May 16, 2019

Was this documentation topic helpful?

Enter your email address, and someone from the documentation team will respond to you:

Please provide your comments here. Ask a question or make a suggestion.

You must be logged into splunk.com in order to post comments. Log in now.

Please try to keep this discussion focused on the content covered in this documentation topic. If you have a more general question about Splunk functionality or are experiencing a difficulty with Splunk, consider posting a question to Splunkbase Answers.

0 out of 1000 Characters