Skip to content

Troubleshooting

No Name edited this page Dec 20, 2018 · 5 revisions

If you are experiencing issues with OSweep, please check the following first:

  • Check the connection to the Internet
  • Ensure that OSweep is installed under $SPLUNK_HOME/etc/apps/osweep
  • Ensure that the correct user recursively owns $SPLUNK_HOME
  • Check the Splunk logs (mainly splunkd.log) under $SPLUNK_HOME/var/log/splunk/ for any Splunk configuration issues

Here are some other issues you might experience:

  • The Feed Overview dashboard is not populating:
    • Try to manually download the feed
      | <OSWEEP_COMMAND> feed
      
  • You're API key is not working:
    • Ensure that the key values are in quotes

Go to Coming Soon

Clone this wiki locally