<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add-on for Microsoft Azure: Is there a reason Splunk keeps retrieving the same data from Azure? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-Is-there-a-reason-Splunk-keeps/m-p/245157#M73706</link>
    <description>&lt;P&gt;Which input are you using?  Also, try running the following search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal sourcetype=splunkd Azure*
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 10 May 2016 21:57:25 GMT</pubDate>
    <dc:creator>jconger</dc:creator>
    <dc:date>2016-05-10T21:57:25Z</dc:date>
    <item>
      <title>Splunk Add-on for Microsoft Azure: Is there a reason Splunk keeps retrieving the same data from Azure?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-Is-there-a-reason-Splunk-keeps/m-p/245156#M73705</link>
      <description>&lt;P&gt;I currently have the Splunk Add-on for Microsoft Azure for Splunk installed, but have noticed that each time it polls, it only retrieves the same set of events repeatedly and has not retrieved any new events since its implementation. I followed the directions in the PDF that comes with the add-on. Any advice would be greatly appreciated!&lt;/P&gt;

&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 10 May 2016 21:09:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-Is-there-a-reason-Splunk-keeps/m-p/245156#M73705</guid>
      <dc:creator>mhazz19087</dc:creator>
      <dc:date>2016-05-10T21:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Azure: Is there a reason Splunk keeps retrieving the same data from Azure?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-Is-there-a-reason-Splunk-keeps/m-p/245157#M73706</link>
      <description>&lt;P&gt;Which input are you using?  Also, try running the following search:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_internal sourcetype=splunkd Azure*
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 10 May 2016 21:57:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-Is-there-a-reason-Splunk-keeps/m-p/245157#M73706</guid>
      <dc:creator>jconger</dc:creator>
      <dc:date>2016-05-10T21:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Azure: Is there a reason Splunk keeps retrieving the same data from Azure?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-Is-there-a-reason-Splunk-keeps/m-p/245158#M73707</link>
      <description>&lt;P&gt;I am using the Azure Audit input.&lt;/P&gt;

&lt;P&gt;When I run that search I get the following error:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;ERROR ExecProcessor - message from "python "C:\Program Files\Splunk\etc\apps\TA-Azure\bin\AzureAudit.py"" 2016-05-11 10:49:00,559 ERROR AzureAudit:410 - Error steaming data: [Error 183] Cannot create a file when that file already exists
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;There are also other licensing and metric entries too and they are all the same.&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2016 14:53:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-Is-there-a-reason-Splunk-keeps/m-p/245158#M73707</guid>
      <dc:creator>mhazz19087</dc:creator>
      <dc:date>2016-05-11T14:53:13Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Azure: Is there a reason Splunk keeps retrieving the same data from Azure?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-Is-there-a-reason-Splunk-keeps/m-p/245159#M73708</link>
      <description>&lt;P&gt;And thank you for your time!&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2016 14:53:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-Is-there-a-reason-Splunk-keeps/m-p/245159#M73708</guid>
      <dc:creator>mhazz19087</dc:creator>
      <dc:date>2016-05-11T14:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Azure: Is there a reason Splunk keeps retrieving the same data from Azure?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-Is-there-a-reason-Splunk-keeps/m-p/245160#M73709</link>
      <description>&lt;P&gt;Take a look!&lt;BR /&gt;
&lt;A href="https://answers.splunk.com/answers/396835/splunk-add-on-for-microsoft-azure-azurewebsitediag.html"&gt;https://answers.splunk.com/answers/396835/splunk-add-on-for-microsoft-azure-azurewebsitediag.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 May 2016 15:25:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-Is-there-a-reason-Splunk-keeps/m-p/245160#M73709</guid>
      <dc:creator>giorgio_adami_m</dc:creator>
      <dc:date>2016-05-11T15:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Azure: Is there a reason Splunk keeps retrieving the same data from Azure?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-Is-there-a-reason-Splunk-keeps/m-p/245161#M73710</link>
      <description>&lt;P&gt;Hello i hit the same issue. The problem it appears because they use os.rename to save information in file, about what is the latest collected data, but in Windows this fails after the first collection. It fails because in windows os.rename can’t save the file if the destination exist.&lt;/P&gt;

&lt;P&gt;You can check the Python Docs : &lt;A href="https://docs.python.org/2/library/os.html"&gt;https://docs.python.org/2/library/os.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;For a workaround i changed the Python script to check if file exist before the rename and if it's existing, the script delete it.&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 09:49:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-Is-there-a-reason-Splunk-keeps/m-p/245161#M73710</guid>
      <dc:creator>danieltodorov</dc:creator>
      <dc:date>2016-05-12T09:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft Azure: Is there a reason Splunk keeps retrieving the same data from Azure?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-Is-there-a-reason-Splunk-keeps/m-p/245162#M73711</link>
      <description>&lt;P&gt;I see what you're referencing, but I cannot locate the file that "already exists". I would prefer not to edit the script if necessary, especially as this isn't the exact same scenario. If I could locate this file I could rename it so that it could be recreated.&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 15:53:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Splunk-Add-on-for-Microsoft-Azure-Is-there-a-reason-Splunk-keeps/m-p/245162#M73711</guid>
      <dc:creator>mhazz19087</dc:creator>
      <dc:date>2016-05-12T15:53:34Z</dc:date>
    </item>
  </channel>
</rss>

