<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting the following error after trying to use Splunk Add-on for SCOM. Downloaded the add-on and modified the inputs.conf and placed it in local folder as per documentation. in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-the-following-error-after-trying-to-use-Splunk-Add-on/m-p/224076#M24682</link>
    <description>&lt;P&gt;I got that error when I first tried to install the TA on a universal forwarder.  But this TA needs to run on a heavy forwarder (or search head etc).  I believe that particular function is doing a rest call against the box to get the splunk version.&lt;/P&gt;

&lt;P&gt;Do you have it installed on a universal forwarder?&lt;/P&gt;</description>
    <pubDate>Sat, 13 Aug 2016 13:45:23 GMT</pubDate>
    <dc:creator>maciep</dc:creator>
    <dc:date>2016-08-13T13:45:23Z</dc:date>
    <item>
      <title>Getting the following error after trying to use Splunk Add-on for SCOM. Downloaded the add-on and modified the inputs.conf and placed it in local folder as per documentation.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-the-following-error-after-trying-to-use-Splunk-Add-on/m-p/224074#M24680</link>
      <description>&lt;P&gt;User script exception: : {"messages":[{"type":"ERROR","text":"\n In handler 'ta_ms_scom_common_serverinfo': Admin handler 'ta_ms_scom_common_serverinfo' not found."}]}&lt;/P&gt;

&lt;P&gt;And found this on ta_scom.log&lt;BR /&gt;
And found this e&lt;BR /&gt;
[ERROR] The remote server returned an error: (404) Not Found.&lt;BR /&gt;
at getSplunkServerVersion, C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_microsoft-scom\bin\scom_command_loader.ps1: line 651&lt;BR /&gt;
at run, C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_microsoft-scom\bin\scom_command_loader.ps1: line 584&lt;BR /&gt;
at , C:\Program Files\SplunkUniversalForwarder\etc\apps\Splunk_TA_microsoft-scom\bin\scom_command_loader.ps1: line 667&lt;BR /&gt;
at , : line 1&lt;BR /&gt;
at , : line 46&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:35:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-the-following-error-after-trying-to-use-Splunk-Add-on/m-p/224074#M24680</guid>
      <dc:creator>sshres5</dc:creator>
      <dc:date>2020-09-29T10:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: Getting the following error after trying to use Splunk Add-on for SCOM. Downloaded the add-on and modified the inputs.conf and placed it in local folder as per documentation.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-the-following-error-after-trying-to-use-Splunk-Add-on/m-p/224075#M24681</link>
      <description>&lt;P&gt;When I modified my inputs.conf on the powershell portion with 'commands' for 'groups', I no longer see this. However, I do not see any logs arriving in my splunk indexer.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Aug 2016 20:34:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-the-following-error-after-trying-to-use-Splunk-Add-on/m-p/224075#M24681</guid>
      <dc:creator>sshres5</dc:creator>
      <dc:date>2016-08-12T20:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: Getting the following error after trying to use Splunk Add-on for SCOM. Downloaded the add-on and modified the inputs.conf and placed it in local folder as per documentation.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-the-following-error-after-trying-to-use-Splunk-Add-on/m-p/224076#M24682</link>
      <description>&lt;P&gt;I got that error when I first tried to install the TA on a universal forwarder.  But this TA needs to run on a heavy forwarder (or search head etc).  I believe that particular function is doing a rest call against the box to get the splunk version.&lt;/P&gt;

&lt;P&gt;Do you have it installed on a universal forwarder?&lt;/P&gt;</description>
      <pubDate>Sat, 13 Aug 2016 13:45:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-the-following-error-after-trying-to-use-Splunk-Add-on/m-p/224076#M24682</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2016-08-13T13:45:23Z</dc:date>
    </item>
    <item>
      <title>Re: Getting the following error after trying to use Splunk Add-on for SCOM. Downloaded the add-on and modified the inputs.conf and placed it in local folder as per documentation.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-the-following-error-after-trying-to-use-Splunk-Add-on/m-p/224077#M24683</link>
      <description>&lt;P&gt;Yes, the server has universal forwarder installed on it. Is there a way to use it on universal forwarder, as the servers with SCOM are using universal forwarder.?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2016 16:30:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-the-following-error-after-trying-to-use-Splunk-Add-on/m-p/224077#M24683</guid>
      <dc:creator>sshres5</dc:creator>
      <dc:date>2016-08-15T16:30:58Z</dc:date>
    </item>
    <item>
      <title>Re: Getting the following error after trying to use Splunk Add-on for SCOM. Downloaded the add-on and modified the inputs.conf and placed it in local folder as per documentation.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-the-following-error-after-trying-to-use-Splunk-Add-on/m-p/224078#M24684</link>
      <description>&lt;P&gt;Not inherently that I could tell.  For example, i think they store the credentials in the rest interface, so you wouldn't be able to do that with a uf.&lt;/P&gt;

&lt;P&gt;I just went ahead and built a Windows heavy forwarder and installed the SCOM console on it.  And so once the TA was installed, I was able to use the app's web interface to configure servers/credentials/inputs.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2016 16:52:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-the-following-error-after-trying-to-use-Splunk-Add-on/m-p/224078#M24684</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2016-08-15T16:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: Getting the following error after trying to use Splunk Add-on for SCOM. Downloaded the add-on and modified the inputs.conf and placed it in local folder as per documentation.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-the-following-error-after-trying-to-use-Splunk-Add-on/m-p/224079#M24685</link>
      <description>&lt;P&gt;In my case, I won't be able to use Windows Heavy Forwarder, as all our search heads are on UNIX systems.&lt;/P&gt;

&lt;P&gt;Do you think there might be other ways to collect data from SCOM and feed it to Splunk?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2016 16:57:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-the-following-error-after-trying-to-use-Splunk-Add-on/m-p/224079#M24685</guid>
      <dc:creator>sshres5</dc:creator>
      <dc:date>2016-08-15T16:57:26Z</dc:date>
    </item>
    <item>
      <title>Re: Getting the following error after trying to use Splunk Add-on for SCOM. Downloaded the add-on and modified the inputs.conf and placed it in local folder as per documentation.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-the-following-error-after-trying-to-use-Splunk-Add-on/m-p/224080#M24686</link>
      <description>&lt;P&gt;Sure, you can probably do something similar to what the TA does.  Because although there seems to be a lot going on with it, it really boils down to running the various scom cmdlets to gather data.&lt;/P&gt;

&lt;P&gt;So you could create your own scripted inputs to run those cmdlets, e.g. get-scomalert, get-scommonitor, get-scomoverride etc.  SCOM has a ton of powershell cmdlets available to gather all sorts of data.  Or set up scheduled tasks to run those cmdlets and output the results to log files and just ingest those log files.&lt;/P&gt;

&lt;P&gt;Also, if you're familiar with the scom database schema and have access to it, you could install the dbconnect app to ingest data directly from the database (personally, I'm not familiar with the database schema).&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2016 22:08:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-the-following-error-after-trying-to-use-Splunk-Add-on/m-p/224080#M24686</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2016-08-15T22:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Getting the following error after trying to use Splunk Add-on for SCOM. Downloaded the add-on and modified the inputs.conf and placed it in local folder as per documentation.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-the-following-error-after-trying-to-use-Splunk-Add-on/m-p/224081#M24687</link>
      <description>&lt;P&gt;I completely skipped the add-on for SCOM. Since the evtx file of SCOM is Operations Manager.evtx, we started monitoring it like the other winevent System/Application logs.&lt;/P&gt;</description>
      <pubDate>Mon, 29 Aug 2016 21:08:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Getting-the-following-error-after-trying-to-use-Splunk-Add-on/m-p/224081#M24687</guid>
      <dc:creator>sshres5</dc:creator>
      <dc:date>2016-08-29T21:08:03Z</dc:date>
    </item>
  </channel>
</rss>

