<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error: read ECONNRESET in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-read-ECONNRESET/m-p/407215#M49643</link>
    <description>&lt;P&gt;I did. It was a firewall issue after all. I didn't see it in the firewall logs initially but after I talked to our networking team, they found some blocked packets going to the Key Vault. After we allowed those, we saw more traffic being blocked, now going to the Event Hub itself.&lt;/P&gt;

&lt;P&gt;Basically, we had to add the following to the Firewall whitelist:&lt;/P&gt;

&lt;P&gt;Dest: yourKeyVaultName.vault.azure.net&lt;BR /&gt;
Service: TCP/443&lt;/P&gt;

&lt;P&gt;Dest: yourEventhubName.servicebus.windows.net&lt;BR /&gt;
Service: TCP/5671&lt;/P&gt;</description>
    <pubDate>Wed, 10 Apr 2019 13:58:57 GMT</pubDate>
    <dc:creator>fredshino</dc:creator>
    <dc:date>2019-04-10T13:58:57Z</dc:date>
    <item>
      <title>Error: read ECONNRESET</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-read-ECONNRESET/m-p/407213#M49641</link>
      <description>&lt;P&gt;Connection reset looks like a networking issue to me but I checked our firewall logs and I don't see any denies on packets sent by our Splunk HF where the add-on is installed.&lt;/P&gt;

&lt;P&gt;Can you give me any guidance on how to troubleshoot this?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;02-25-2019 09:45:35.922 -0500 ERROR ExecProcessor - message from "/Data/splunk/etc/apps/TA-Azure_Monitor/bin/azure_activity_log.sh" Modular input azure_activity_log://***** Error getting event hub creds: RequestError: Error: read ECONNRESET
02-25-2019 09:46:35.855 -0500 ERROR ExecProcessor - message from "/Data/splunk/etc/apps/TA-Azure_Monitor/bin/azure_diagnostic_logs.sh" Modular input azure_diagnostic_logs://***** Diag Logs Error getting event hub creds: RequestError: Error: read ECONNRESET
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 25 Feb 2019 14:53:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-read-ECONNRESET/m-p/407213#M49641</guid>
      <dc:creator>fredshino</dc:creator>
      <dc:date>2019-02-25T14:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: Error: read ECONNRESET</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-read-ECONNRESET/m-p/407214#M49642</link>
      <description>&lt;P&gt;Did you find a solution to this? I'm receiving the same error on my instance.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 13:47:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-read-ECONNRESET/m-p/407214#M49642</guid>
      <dc:creator>rmoss84</dc:creator>
      <dc:date>2019-04-10T13:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: Error: read ECONNRESET</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-read-ECONNRESET/m-p/407215#M49643</link>
      <description>&lt;P&gt;I did. It was a firewall issue after all. I didn't see it in the firewall logs initially but after I talked to our networking team, they found some blocked packets going to the Key Vault. After we allowed those, we saw more traffic being blocked, now going to the Event Hub itself.&lt;/P&gt;

&lt;P&gt;Basically, we had to add the following to the Firewall whitelist:&lt;/P&gt;

&lt;P&gt;Dest: yourKeyVaultName.vault.azure.net&lt;BR /&gt;
Service: TCP/443&lt;/P&gt;

&lt;P&gt;Dest: yourEventhubName.servicebus.windows.net&lt;BR /&gt;
Service: TCP/5671&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 13:58:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-read-ECONNRESET/m-p/407215#M49643</guid>
      <dc:creator>fredshino</dc:creator>
      <dc:date>2019-04-10T13:58:57Z</dc:date>
    </item>
    <item>
      <title>Re: Error: read ECONNRESET</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-read-ECONNRESET/m-p/407216#M49644</link>
      <description>&lt;P&gt;Awesome. Looking at our traffic, we've got the same issue. Thank you for your answer. This should solve our problems as well.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2019 15:33:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Error-read-ECONNRESET/m-p/407216#M49644</guid>
      <dc:creator>rmoss84</dc:creator>
      <dc:date>2019-04-10T15:33:13Z</dc:date>
    </item>
  </channel>
</rss>

