<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450139#M55396</link>
    <description>&lt;P&gt;Sometimes, it breaks in 2-4 days, sometimes in 15-16 hours.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Sep 2018 08:37:56 GMT</pubDate>
    <dc:creator>phularah</dc:creator>
    <dc:date>2018-09-11T08:37:56Z</dc:date>
    <item>
      <title>Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450119#M55376</link>
      <description>&lt;P&gt;Are there any specific ports or specific permissions this add-on requires/uses, so that I can inform the team, so if any modifications are made data flow is not interrupted.&lt;/P&gt;

&lt;P&gt;I have configured Microsoft Log Analytics Add-on in Heavy Forwarder and forwarding the logs received to indexer. There is no clustering. I would like to hear from @jkat54 and @dpanych. Any ideas, why this keep on happening.&lt;/P&gt;

&lt;P&gt;I used&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal log_level=err* OR log_level=warn loganalytics*
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The latest event I am getting some results using this query is&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;09-05-2018 18:24:24.168 +0200 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\TA-ms-loganalytics\bin\log_analytics.py" ERROR('Connection broken: IncompleteRead(0 bytes read)', IncompleteRead(0 bytes read))
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 06 Sep 2018 06:56:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450119#M55376</guid>
      <dc:creator>phularah</dc:creator>
      <dc:date>2018-09-06T06:56:26Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450120#M55377</link>
      <description>&lt;P&gt;It connects to the log analytics API on TCP port 443 aka HTTPS.&lt;/P&gt;

&lt;P&gt;Nothing else is needed.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 07:56:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450120#M55377</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-09-06T07:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450121#M55378</link>
      <description>&lt;P&gt;I am not sure why is it happening then. I tried making a new input but still I am unable to see any data. Any idea why it might be happening?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 08:15:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450121#M55378</guid>
      <dc:creator>phularah</dc:creator>
      <dc:date>2018-09-06T08:15:02Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450122#M55379</link>
      <description>&lt;P&gt;After making new inputs and deleting old inputs, I am getting data now. But, I don't know why it stopped in the first place and now after first making a new input and disabling previous input, data didn't come. I again made a new input after deleting all disabled inputs, now I am getting data. It is really frustrating, and I am unable to pinpoint the source. &lt;/P&gt;

&lt;P&gt;Now, new results are coming where log_level=warn, &lt;/P&gt;

&lt;P&gt;09-06-2018 10:50:34.492 +0200 WARN  LineBreakingProcessor - Truncating line because limit of 10000 bytes has been exceeded with a line length &amp;gt;= 14261 - data_source="log_analytics://analytics", data_host="Hostname", data_sourcetype="loganalytics" &lt;/P&gt;

&lt;P&gt;but it is of no concern, my concern is this error. &lt;BR /&gt;
Could you please tell why this error might show up.&lt;/P&gt;

&lt;P&gt;09-05-2018 18:24:24.168 +0200 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\TA-ms-loganalytics\bin\log_analytics.py" ERROR('Connection broken: IncompleteRead(0 bytes read)', IncompleteRead(0 bytes read))&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:11:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450122#M55379</guid>
      <dc:creator>phularah</dc:creator>
      <dc:date>2020-09-29T21:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450123#M55380</link>
      <description>&lt;P&gt;Sounds like the checkpoints were messed up.  Did you upgrade from a previous version of the app or install fresh/new?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 10:33:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450123#M55380</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-09-06T10:33:05Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450124#M55381</link>
      <description>&lt;P&gt;Yes, I had upgraded the add-on. I was using the latest add-on before this problem surfaced.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 10:36:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450124#M55381</guid>
      <dc:creator>phularah</dc:creator>
      <dc:date>2018-09-06T10:36:03Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450125#M55382</link>
      <description>&lt;P&gt;Ok looks like the process for upgrading should have been to delete the inputs, upgrade the app, add the inputs.&lt;/P&gt;

&lt;P&gt;this is due to the way the checkpoints changed between versions.  My apologies for the inconvenience.  &lt;/P&gt;

&lt;P&gt;Is every input you’ve re-added working now?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Sep 2018 14:58:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450125#M55382</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-09-06T14:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450126#M55383</link>
      <description>&lt;P&gt;Was everything working after removing and adding the inputs after the upgrade?&lt;/P&gt;</description>
      <pubDate>Sat, 08 Sep 2018 11:32:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450126#M55383</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-09-08T11:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450127#M55384</link>
      <description>&lt;P&gt;no...again  we faced an issue..data again stopped coming even though we haven't changed anything..&lt;BR /&gt;
We are receiving below errors from sourcetype="ta:ms:loganalytics:log"&lt;/P&gt;

&lt;P&gt;2018-09-10 08:01:40,148 ERROR pid=11372 tid=MainThread file=base_modinput.py:log_error:307 | Get error when collecting events.&lt;BR /&gt;
Traceback (most recent call last):&lt;BR /&gt;
  File "F:\Splunk\etc\apps\TA-ms-loganalytics\bin\ta_ms_loganalytics\modinput_wrapper\base_modinput.py", line 127, in stream_events&lt;BR /&gt;
    self.collect_events(ew)&lt;BR /&gt;
  File "F:\Splunk\etc\apps\TA-ms-loganalytics\bin\log_analytics.py", line 96, in collect_events&lt;BR /&gt;
    input_module.collect_events(self, ew)&lt;BR /&gt;
  File "F:\Splunk\etc\apps\TA-ms-loganalytics\bin\input_module_log_analytics.py", line 49, in collect_events&lt;BR /&gt;
    token_response = context.acquire_token_with_client_credentials('&lt;A href="https://api.loganalytics.io/" target="_blank"&gt;https://api.loganalytics.io/&lt;/A&gt;', application_id, application_key)&lt;BR /&gt;
  File "F:\Splunk\etc\apps\TA-ms-loganalytics\bin\adal\authentication_context.py", line 160, in acquire_token_with_client_credentials&lt;BR /&gt;
    return self._acquire_token(token_func)&lt;BR /&gt;
  File "F:\Splunk\etc\apps\TA-ms-loganalytics\bin\adal\authentication_context.py", line 109, in _acquire_token&lt;BR /&gt;
    return token_func(self)&lt;BR /&gt;
  File "F:\Splunk\etc\apps\TA-ms-loganalytics\bin\adal\authentication_context.py", line 158, in token_func&lt;BR /&gt;
    return token_request.get_token_with_client_credentials(client_secret)&lt;BR /&gt;
  File "F:\Splunk\etc\apps\TA-ms-loganalytics\bin\adal\token_request.py", line 316, in get_token_with_client_credentials&lt;BR /&gt;
    token = self._oauth_get_token(oauth_parameters)&lt;BR /&gt;
  File "F:\Splunk\etc\apps\TA-ms-loganalytics\bin\adal\token_request.py", line 113, in _oauth_get_token&lt;BR /&gt;
    return client.get_token(oauth_parameters)&lt;BR /&gt;
  File "F:\Splunk\etc\apps\TA-ms-loganalytics\bin\adal\oauth2_client.py", line 281, in get_token&lt;BR /&gt;
    raise AdalError(return_error_string, error_response)&lt;BR /&gt;
AdalError: Get Token request returned http error: 400 and server response: {"error":"unauthorized_client","error_description":"AADSTS70001: Application with identifier '37e37c43-5946-483a-a856-041490e76e8cccc' was not found in the directory 30f52344-4663-4c2e-bab3-61bf24ebbed8\r\nTrace ID: 3cdc5a4c-98df-4102-916f-779ce15e0500\r\nCorrelation ID: 403f848a-a918-4d61-8a85-164c1df79e29\r\nTimestamp: 2018-09-10 06:01:40Z","error_codes":[70001],"timestamp":"2018-09-10 06:01:40Z","trace_id":"3cdc5a4c-98df-4102-916f-779ce15e0500","correlation_id":"403f848a-a918-4d61-8a85-164c1df79e29"}&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:12:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450127#M55384</guid>
      <dc:creator>phularah</dc:creator>
      <dc:date>2020-09-29T21:12:48Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450128#M55385</link>
      <description>&lt;P&gt;Also, for source=splunkd, we are getting these messages&lt;/P&gt;

&lt;P&gt;09-10-2018 08:02:41.053 +0200 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\TA-ms-loganalytics\bin\log_analytics.py" ERRORGet Token request returned http error: 400 and server response: {"error":"unauthorized_client","error_description":"AADSTS70001: Application with identifier '37e37c43-5946-483a-a856-041490e76e8cccc' was not found in the directory 30f52344-4663-4c2e-bab3-61bf24ebbed8\r\nTrace ID: 4327f55a-bb53-4606-b506-66fc1b4e0500\r\nCorrelation ID: 6ec81c9d-4f8a-47ea-84b4-2ad2b7e40a3e\r\nTimestamp: 2018-09-10 06:02:40Z","error_codes":[70001],"timestamp":"2018-09-10 06:02:40Z","trace_id":"4327f55a-bb53-4606-b506-66fc1b4e0500","correlation_id":"6ec81c9d-4f8a-47ea-84b4-2ad2b7e40a3e"}&lt;/P&gt;

&lt;P&gt;09-10-2018 08:02:40.553 +0200 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\TA-ms-loganalytics\bin\log_analytics.py"     raise AdalError(return_error_string, error_response)&lt;/P&gt;

&lt;P&gt;09-10-2018 08:02:40.553 +0200 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\TA-ms-loganalytics\bin\log_analytics.py"   File "F:\Splunk\etc\apps\TA-ms-loganalytics\bin\adal\oauth2_client.py", line 281, in get_token&lt;/P&gt;

&lt;P&gt;09-10-2018 08:02:40.553 +0200 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\TA-ms-loganalytics\bin\log_analytics.py"     return client.get_token(oauth_parameters)&lt;/P&gt;

&lt;P&gt;09-10-2018 08:02:40.553 +0200 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\TA-ms-loganalytics\bin\log_analytics.py"   File "F:\Splunk\etc\apps\TA-ms-loganalytics\bin\adal\token_request.py", line 113, in _oauth_get_token&lt;/P&gt;

&lt;P&gt;09-10-2018 08:02:40.553 +0200 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\TA-ms-loganalytics\bin\log_analytics.py"     token = self._oauth_get_token(oauth_parameters)&lt;/P&gt;

&lt;P&gt;09-10-2018 08:02:40.553 +0200 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\TA-ms-loganalytics\bin\log_analytics.py"   File "F:\Splunk\etc\apps\TA-ms-loganalytics\bin\adal\token_request.py", line 316, in get_token_with_client_credentials&lt;/P&gt;

&lt;P&gt;09-10-2018 08:02:40.553 +0200 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\TA-ms-loganalytics\bin\log_analytics.py"     return token_request.get_token_with_client_credentials(client_secret)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:12:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450128#M55385</guid>
      <dc:creator>phularah</dc:creator>
      <dc:date>2020-09-29T21:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450129#M55386</link>
      <description>&lt;P&gt;@jkat54,&lt;BR /&gt;
is there any retry attempts for input in OMS?&lt;BR /&gt;
like due to some reason in oms, splunk unable to collect data for 5 min. but after 5 min. everything fine at OMS side...but then splunk unable to receive any kind of data ..it get stopped so is there any retry attempt like it will try to connect with OMS for few attempts and then it will stop attemptting to connect with OMS?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 06:59:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450129#M55386</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2018-09-10T06:59:40Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450130#M55387</link>
      <description>&lt;P&gt;The “connection broken” error suggests a proxy or firewall or other network issue.&lt;/P&gt;

&lt;P&gt;No one else is reporting this error so I believe it to be something with your environment only.&lt;/P&gt;

&lt;P&gt;As for if the add on retries connections, no it only attempts one connection per interval. &lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 10:26:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450130#M55387</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-09-10T10:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450131#M55388</link>
      <description>&lt;P&gt;Wait... this question wasn’t by you.  @493669 do you work with phularah?&lt;/P&gt;

&lt;P&gt;If not, you should create your own question.&lt;/P&gt;

&lt;P&gt;If yes, then see this link for how to resolve the error you have: &lt;A href="https://docs.microsoft.com/en-us/azure/active-directory/application-sign-in-problem-federated-sso-gallery#application-not-found-in-directory"&gt;https://docs.microsoft.com/en-us/azure/active-directory/application-sign-in-problem-federated-sso-gallery#application-not-found-in-directory&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 11:02:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450131#M55388</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-09-10T11:02:57Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450132#M55389</link>
      <description>&lt;P&gt;Yes, @jkat me and @493669 are working together. My comments were sent to moderator, so I asked my colleague @493669 to post these comments. Now, I can see my posted comments.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 11:07:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450132#M55389</guid>
      <dc:creator>phularah</dc:creator>
      <dc:date>2018-09-10T11:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450133#M55390</link>
      <description>&lt;P&gt;@jkat54 , but if we have any error at oms side then data will not come... but after I deleted previous input and created new input , data started flowing again...so it doesn't seems to be issue at OMS side..isn't it?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 11:21:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450133#M55390</guid>
      <dc:creator>phularah</dc:creator>
      <dc:date>2018-09-10T11:21:32Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450134#M55391</link>
      <description>&lt;P&gt;When you recreate do you recreate in splunk only?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 11:45:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450134#M55391</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-09-10T11:45:08Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450135#M55392</link>
      <description>&lt;P&gt;Yes, we create new inputs in Splunk only.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Sep 2018 11:49:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450135#M55392</guid>
      <dc:creator>phularah</dc:creator>
      <dc:date>2018-09-10T11:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450136#M55393</link>
      <description>&lt;P&gt;can you please share your take on this, why it might be happening? I had a chat with Azure guys in my team, they say everything is working fine at their side and they are not making any changes.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 05:37:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450136#M55393</guid>
      <dc:creator>phularah</dc:creator>
      <dc:date>2018-09-11T05:37:01Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450137#M55394</link>
      <description>&lt;P&gt;Also, we are getting these messages running this query, index=_internal log_level=err* loganalytics*. Again after working for a few hours data has again stopped coming.&lt;/P&gt;

&lt;P&gt;These are the error messages, we are getting:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;9/11/18
5:59:55.927 AM  
09-11-2018 05:59:55.927 +0200 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\TA-ms-loganalytics\bin\log_analytics.py" UnboundLocalError: local variable 'data' referenced before assignment

    host =  *****   
    source =    F:\Splunk\var\log\splunk\splunkd.log    
    sourcetype =    splunkd 

    9/11/18
5:59:55.927 AM  
09-11-2018 05:59:55.927 +0200 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\TA-ms-loganalytics\bin\log_analytics.py"     for i in range(len(data["tables"][0]["rows"])):

    host =  ********    
    source =    F:\Splunk\var\log\splunk\splunkd.log    
    sourcetype =    splunkd 

    9/11/18
5:59:55.927 AM  
09-11-2018 05:59:55.927 +0200 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\TA-ms-loganalytics\bin\log_analytics.py"   File "F:\Splunk\etc\apps\TA-ms-loganalytics\bin\input_module_log_analytics.py", line 86, in collect_events

    host =  ******  
    source =    F:\Splunk\var\log\splunk\splunkd.log    
    sourcetype =    splunkd 

    9/11/18
5:59:55.927 AM  
09-11-2018 05:59:55.927 +0200 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\TA-ms-loganalytics\bin\log_analytics.py"     input_module.collect_events(self, ew)

    host =  *****
    source =    F:\Splunk\var\log\splunk\splunkd.log    
    sourcetype =    splunkd 

    9/11/18
5:59:55.927 AM  
09-11-2018 05:59:55.927 +0200 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\TA-ms-loganalytics\bin\log_analytics.py"   File "F:\Splunk\etc\apps\TA-ms-loganalytics\bin\log_analytics.py", line 96, in collect_events

    host =  *****
    source =    F:\Splunk\var\log\splunk\splunkd.log    
    sourcetype =    splunkd 

    9/11/18
5:59:55.927 AM  
09-11-2018 05:59:55.927 +0200 ERROR ExecProcessor - message from "python F:\Splunk\etc\apps\TA-ms-loganalytics\bin\log_analytics.py"     self.collect_events(ew)

    host =  *******
    source =    F:\Splunk\var\log\splunk\splunkd.log    
    sourcetype =    splunkd 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 21:10:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450137#M55394</guid>
      <dc:creator>phularah</dc:creator>
      <dc:date>2020-09-29T21:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Log Analytics Ad-on: Why does the data stop coming in Splunk after firewall rules are modified in OMS?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450138#M55395</link>
      <description>&lt;P&gt;This means the query didn’t return any results.&lt;/P&gt;

&lt;P&gt;Any idea how long it takes before it breaks?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2018 08:34:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Microsoft-Log-Analytics-Ad-on-Why-does-the-data-stop-coming-in/m-p/450138#M55395</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-09-11T08:34:27Z</dc:date>
    </item>
  </channel>
</rss>

