<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Connect for Zoom in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-for-Zoom/m-p/509723#M62525</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/144180"&gt;@pastorlibre&lt;/a&gt;&amp;nbsp; The zoom admin pointed the "&lt;STRONG&gt;Event Notification Endpoint URL"&lt;/STRONG&gt; to Splunk server DNS/Load balancer running "Splunk Connect for Zoom" on tcp 4443 and after granting network access to&amp;nbsp;&lt;A href="https://marketplace.zoom.us/docs/api-reference/webhook-reference#ip-addresses," target="_blank"&gt;https://marketplace.zoom.us/docs/api-reference/webhook-reference#ip-addresses,&lt;/A&gt;&lt;/P&gt;&lt;P&gt;started to see series="zoom:webhook" events in metrics.log and sourcetype=zoom:webhook was searchable.&lt;/P&gt;&lt;P&gt;But now from splunkd.log, not seeing the http_500 code or the large +300MB. But seeing lots of:&lt;/P&gt;&lt;P&gt;07-17-2020 14:35:46.095 +0000 ERROR ExecProcessor - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/Splunk_Connect_zoom/bin/zoom_input.py" 3.235.69.93 - - [17/Jul/2020 14:35:45] "POST / HTTP/1.1" 200 -&lt;BR /&gt;07-17-2020 14:35:46.095 +0000 ERROR ExecProcessor - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/Splunk_Connect_zoom/bin/zoom_input.py" 3.211.241.118 - - [17/Jul/2020 14:35:45] "POST / HTTP/1.1" 200 -&lt;BR /&gt;07-17-2020 14:35:46.095 +0000 ERROR ExecProcessor - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/Splunk_Connect_zoom/bin/zoom_input.py" 3.235.69.92 - - [17/Jul/2020 14:35:46] "POST / HTTP/1.1" 200 -&lt;BR /&gt;07-17-2020 14:35:46.095 +0000 ERROR ExecProcessor - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/Splunk_Connect_zoom/bin/zoom_input.py" 3.235.69.93 - - [17/Jul/2020 14:35:46] "POST / HTTP/1.1" 200 -&lt;BR /&gt;I will open case with Splunk support.&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jul 2020 14:49:12 GMT</pubDate>
    <dc:creator>lim2</dc:creator>
    <dc:date>2020-07-17T14:49:12Z</dc:date>
    <item>
      <title>Splunk Connect for Zoom</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-for-Zoom/m-p/494054#M60787</link>
      <description>&lt;P&gt;Is anyone able to pull logs using Splunk Connect for Zoom. I have installed the app and configured as per documentation , also have created webhook only app in Zoom and subscribed the events for Splunk endpoint, I still cannot see anything in my index. Please let me know if it is working for you.&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2020 23:09:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-for-Zoom/m-p/494054#M60787</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2020-05-05T23:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Connect for Zoom</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-for-Zoom/m-p/494055#M60788</link>
      <description>&lt;P&gt;Are you seeing any error messages in yiur splunkd logs for it? They can help you to get to the solution.&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 08:01:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-for-Zoom/m-p/494055#M60788</guid>
      <dc:creator>shivanshu1593</dc:creator>
      <dc:date>2020-05-06T08:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Connect for Zoom</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-for-Zoom/m-p/494056#M60789</link>
      <description>&lt;P&gt;The only WARN message I see is "Socket error from  while accessing  /services/storage/passwords/..".  There is no passwords.conf in this app folder although it gets created under search app, which I don't understand why.&lt;/P&gt;</description>
      <pubDate>Wed, 06 May 2020 15:17:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-for-Zoom/m-p/494056#M60789</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2020-05-06T15:17:43Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Connect for Zoom</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-for-Zoom/m-p/494057#M60790</link>
      <description>&lt;P&gt;is splunk listening on the port? use &lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;netstat -an | grep [whatever port you&lt;BR /&gt;
specified]&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;In zoom you can check the call logs:&lt;BR /&gt;
&lt;A href="https://marketplace.zoom.us/user/logs"&gt;https://marketplace.zoom.us/user/logs&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 May 2020 13:12:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-for-Zoom/m-p/494057#M60790</guid>
      <dc:creator>wgawhh5hbnht</dc:creator>
      <dc:date>2020-05-11T13:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Connect for Zoom</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-for-Zoom/m-p/494058#M60791</link>
      <description>&lt;P&gt;The Splunk connect for Zoom, had a bug which creates a password.conf file in your search app causing errors for reading password in logs. We opened a ticket with Splunk and they are working on fix, updated version shall soon be released. Hence closing this thread.&lt;/P&gt;</description>
      <pubDate>Mon, 25 May 2020 01:12:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-for-Zoom/m-p/494058#M60791</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2020-05-25T01:12:19Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Connect for Zoom</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-for-Zoom/m-p/507098#M62300</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80230"&gt;@Vijeta&lt;/a&gt;&amp;nbsp;, Could you or someone advise what was the fix? Still seeing &lt;FONT size="2"&gt;Splunk Connect for Zoom Version 1.0.1 April 23, 2020.&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;Anyone has to allow Zoom events traffic from &lt;A href="https://marketplace.zoom.us" target="_blank"&gt;https://marketplace.zoom.us/user/logs &lt;U&gt;to be sent to one's Internal Splunk HF running&lt;/U&gt;&lt;/A&gt; Splunk connect for Zoom listening on 4443?&lt;BR /&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT size="2"&gt;Thanks&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jul 2020 14:26:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-for-Zoom/m-p/507098#M62300</guid>
      <dc:creator>lim2</dc:creator>
      <dc:date>2020-07-02T14:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Connect for Zoom</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-for-Zoom/m-p/507367#M62325</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/208943"&gt;@lim2&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue which I was seeing is when configuring Data inputs for Zoom on Splunk Heavy forwarder UI, it was creating passwords.conf file in the et/apps/search folder instead of Zoom app. After raising the ticket with Splunk, they provided with an updated python script to be used in the Zoom app instead of previous one. Post the update the issue related to file creation in search app was not there, but I am still getting 500 error from the Zoom web hook. This can be seen in marketplace.zoom.us under Webhook logs, it shows all the responses but with status code 500, so nothing gets ingested to Splunk. I have opened ticket with Zoom but haven't received any response. It does not seem to be a Splunk issue any more but may be a firewall issue or something not sure.&lt;/P&gt;&lt;P&gt;I would suggest you to open support ticket with Splunk, and they can provide you updated python or look into your issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jul 2020 19:22:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-for-Zoom/m-p/507367#M62325</guid>
      <dc:creator>Vijeta</dc:creator>
      <dc:date>2020-07-04T19:22:26Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Connect for Zoom</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-for-Zoom/m-p/509609#M62512</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80230"&gt;@Vijeta&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/208943"&gt;@lim2&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am also seeing error 500 on my ZOOM Splunk Webhook. did you get any further on this one? I am not seeing any data ingested. However I see in the log the password issue but also the following&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TcpInputProc - Message rejected. Received unexpected message of size=369296128 bytes from src=3.211.241.114:36520 in streaming mode. Maximum message size allowed=67108864. (::) Possible invalid source sending data to splunktcp port or valid source sending unsupported payload.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These started happening as soon as I opened up the port, Is there a place I should be putting a token key?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2020 20:57:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-for-Zoom/m-p/509609#M62512</guid>
      <dc:creator>pastorlibre</dc:creator>
      <dc:date>2020-07-16T20:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Connect for Zoom</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-for-Zoom/m-p/509723#M62525</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/144180"&gt;@pastorlibre&lt;/a&gt;&amp;nbsp; The zoom admin pointed the "&lt;STRONG&gt;Event Notification Endpoint URL"&lt;/STRONG&gt; to Splunk server DNS/Load balancer running "Splunk Connect for Zoom" on tcp 4443 and after granting network access to&amp;nbsp;&lt;A href="https://marketplace.zoom.us/docs/api-reference/webhook-reference#ip-addresses," target="_blank"&gt;https://marketplace.zoom.us/docs/api-reference/webhook-reference#ip-addresses,&lt;/A&gt;&lt;/P&gt;&lt;P&gt;started to see series="zoom:webhook" events in metrics.log and sourcetype=zoom:webhook was searchable.&lt;/P&gt;&lt;P&gt;But now from splunkd.log, not seeing the http_500 code or the large +300MB. But seeing lots of:&lt;/P&gt;&lt;P&gt;07-17-2020 14:35:46.095 +0000 ERROR ExecProcessor - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/Splunk_Connect_zoom/bin/zoom_input.py" 3.235.69.93 - - [17/Jul/2020 14:35:45] "POST / HTTP/1.1" 200 -&lt;BR /&gt;07-17-2020 14:35:46.095 +0000 ERROR ExecProcessor - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/Splunk_Connect_zoom/bin/zoom_input.py" 3.211.241.118 - - [17/Jul/2020 14:35:45] "POST / HTTP/1.1" 200 -&lt;BR /&gt;07-17-2020 14:35:46.095 +0000 ERROR ExecProcessor - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/Splunk_Connect_zoom/bin/zoom_input.py" 3.235.69.92 - - [17/Jul/2020 14:35:46] "POST / HTTP/1.1" 200 -&lt;BR /&gt;07-17-2020 14:35:46.095 +0000 ERROR ExecProcessor - message from "/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/Splunk_Connect_zoom/bin/zoom_input.py" 3.235.69.93 - - [17/Jul/2020 14:35:46] "POST / HTTP/1.1" 200 -&lt;BR /&gt;I will open case with Splunk support.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 14:49:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Connect-for-Zoom/m-p/509723#M62525</guid>
      <dc:creator>lim2</dc:creator>
      <dc:date>2020-07-17T14:49:12Z</dc:date>
    </item>
  </channel>
</rss>

