<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Errors after Microsoft Azure Add on for Splunk upgrade in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/575025#M75545</link>
    <description>&lt;P&gt;In Splunk Cloud.&lt;/P&gt;&lt;P&gt;Is it possible to be a new feature of the add-on?&lt;/P&gt;</description>
    <pubDate>Tue, 16 Nov 2021 11:54:43 GMT</pubDate>
    <dc:creator>andreeaf1301</dc:creator>
    <dc:date>2021-11-16T11:54:43Z</dc:date>
    <item>
      <title>Errors after Microsoft Azure Add on for Splunk upgrade</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/574571#M75521</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We upgraded&amp;nbsp;Microsoft Azure Add on for Splunk to the latest version 3.2.0&lt;/P&gt;&lt;P&gt;After the upgrade, we started seeing the following errors:&lt;/P&gt;&lt;DIV class=""&gt;From {/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/TA-MS-AAD/bin/TA_MS_AAD_rh_settings.py persistent}: "Failed to get password of realm=%s, user=%s." % (self._realm, user)&lt;/DIV&gt;&lt;DIV class=""&gt;From {/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/TA-MS-AAD/bin/TA_MS_AAD_rh_settings.py persistent}: File "/opt/splunk/etc/apps/TA-MS-AAD/bin/ta_ms_aad/aob_py3/solnlib/utils.py", line 148, in wrapper&lt;/DIV&gt;&lt;DIV class=""&gt;From {/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/TA-MS-AAD/bin/TA_MS_AAD_rh_settings.py persistent}: .&lt;/DIV&gt;&lt;DIV class=""&gt;From {/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/TA-MS-AAD/bin/TA_MS_AAD_rh_settings.py persistent}: WARNING:root:Run function: get_password failed: Traceback (most recent call last):&lt;/DIV&gt;&lt;DIV class=""&gt;From {/opt/splunk/bin/python3.7 /opt/splunk/etc/apps/TA-MS-AAD/bin/TA_MS_AAD_rh_settings.py persistent}: solnlib.credentials.CredentialNotExistException: Failed to get password of realm=__REST_CREDENTIAL__#TA-MS-AAD#configs/conf-ta_ms_aad_settings, user=proxy.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;I tried to add again the credentials and re-create the inputs, but still getting them.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;We are getting the logs, but I'm not sure if this errors is impacting us/if we are getting all the logs or how should we correct it.&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Thank you,&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Andreea&lt;/DIV&gt;</description>
      <pubDate>Thu, 11 Nov 2021 13:35:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/574571#M75521</guid>
      <dc:creator>andreeaf1301</dc:creator>
      <dc:date>2021-11-11T13:35:06Z</dc:date>
    </item>
    <item>
      <title>Re: Errors after Microsoft Azure Add on for Splunk upgrade</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/575020#M75544</link>
      <description>&lt;P&gt;Curious - is this in Splunk Cloud or is this add-on installed to your own installation of Splunk?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 11:35:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/575020#M75544</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2021-11-16T11:35:50Z</dc:date>
    </item>
    <item>
      <title>Re: Errors after Microsoft Azure Add on for Splunk upgrade</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/575025#M75545</link>
      <description>&lt;P&gt;In Splunk Cloud.&lt;/P&gt;&lt;P&gt;Is it possible to be a new feature of the add-on?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 11:54:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/575025#M75545</guid>
      <dc:creator>andreeaf1301</dc:creator>
      <dc:date>2021-11-16T11:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: Errors after Microsoft Azure Add on for Splunk upgrade</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/575036#M75546</link>
      <description>&lt;P&gt;I don't know about the features of the app/add-on. I've found the developer and asked them to peek at this conversation to help.&lt;/P&gt;&lt;P&gt;Meanwhile, if it's Cloud you may want to add more details to help the developer understand what's going on. Is it Classic or Victoria? This page will help answer that:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/Experience" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/Admin/Experience&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How frequently do you see these error messages occurring? What search did you run to see them?&lt;/P&gt;&lt;P&gt;It's possible that the app upgrade is not related and rather this may be something that has been occurring for a while but only noticed recently. I say this because you highlighted that the data is still working and you only recently noticed these errors.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 12:58:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/575036#M75546</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2021-11-16T12:58:55Z</dc:date>
    </item>
    <item>
      <title>Re: Errors after Microsoft Azure Add on for Splunk upgrade</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/575043#M75547</link>
      <description>&lt;P&gt;- It is classic;&lt;/P&gt;&lt;P&gt;- We are usually classifying the errors we have in our environment with priorities from high to noise. A report is ran and reviewed everyday and&amp;nbsp; everything that was never seen before, appears as new. When we had the upgrade of the add-on to the latest version, I started seeing these errors.&lt;/P&gt;&lt;P&gt;I started investigating them by using the following searches and the date when the errors started to appear matches the timestamp of the upgrade.&lt;/P&gt;&lt;P&gt;index=_internal sourcetype=splunkd "splunk/etc/apps/TA-MS-AAD/bin/TA_MS_AAD_rh_settings.py" log_level=error component=PersistentScript&lt;/P&gt;&lt;P&gt;index=_internal sourcetype=splunkd ""Failed to get password of realm=%s, user=%s." % (self._realm, user)" component=PersistentScript log_level=error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Right after the upgrade,&amp;nbsp;the data collection was stopped.&lt;/P&gt;&lt;P&gt;I added again the credentials and the feeds were back to normal, but the errors are still coming.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm concerned with them because I don't know if there is any impact in the data we are collecting and I wasn't able to find anything in the documentation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 13:21:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/575043#M75547</guid>
      <dc:creator>andreeaf1301</dc:creator>
      <dc:date>2021-11-16T13:21:19Z</dc:date>
    </item>
    <item>
      <title>Re: Errors after Microsoft Azure Add on for Splunk upgrade</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/575072#M75550</link>
      <description>&lt;P&gt;One more question - did you notice which host the errors are coming from? I ask because it's possible the add-on is on the search head for it's knowledge objects but the inputs.conf are all stripped away, which might be causing some exceptions.&lt;/P&gt;&lt;P&gt;In Classic, data collection add-ons are installed and managed on the Inputs Data Manager (IDM) so I assume everything on that host is working ok?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 15:34:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/575072#M75550</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2021-11-16T15:34:29Z</dc:date>
    </item>
    <item>
      <title>Re: Errors after Microsoft Azure Add on for Splunk upgrade</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/575075#M75551</link>
      <description>&lt;P&gt;We have the add-on installed and configured on IDM. That's where the errors are coming from.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Nov 2021 15:42:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/575075#M75551</guid>
      <dc:creator>andreeaf1301</dc:creator>
      <dc:date>2021-11-16T15:42:15Z</dc:date>
    </item>
    <item>
      <title>Re: Errors after Microsoft Azure Add on for Splunk upgrade</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/575115#M75554</link>
      <description>&lt;P&gt;The error messages are erroneous.&amp;nbsp;&lt;/P&gt;&lt;P&gt;TL;DR = to work around this issue, add the following in &lt;FONT face="courier new,courier"&gt;local/ta_ms_aad_settings.conf&lt;/FONT&gt;:&lt;/P&gt;&lt;DIV&gt;&lt;PRE&gt;&lt;SPAN&gt;[proxy]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;proxy_password&lt;/SPAN&gt;&lt;SPAN&gt; = None&lt;/SPAN&gt;&lt;/PRE&gt;&lt;DIV&gt;&lt;SPAN&gt;This error is caused by a library used by add-ons built with add-on builder (a.k.a. AoB) that implement a proxy.&amp;nbsp; In a nutshell, the REST handler settings code generated by AoB (in this case TA_MS_AAD_rh_settings.py) defines the proxy fields.&amp;nbsp; Here is what it looks like for proxy_password:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;field.RestField(
    'proxy_password',
    required=False,
    encrypted=True,
    default=None,
    validator=validator.String(
        min_len=0, 
        max_len=8192, 
    )
)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;The proxy_password settings specify that the field is not required, but the field is encrypted.&amp;nbsp; Now, getting back to the library code.&amp;nbsp; The library is trying to decrypt proxy settings even if you haven't specified any.&amp;nbsp; An internal bug has been filed, but the workaround should stop the (erroneous) error messages.&lt;/DIV&gt;</description>
      <pubDate>Tue, 16 Nov 2021 23:23:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/575115#M75554</guid>
      <dc:creator>jconger</dc:creator>
      <dc:date>2021-11-16T23:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: Errors after Microsoft Azure Add on for Splunk upgrade</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/585717#M76125</link>
      <description>&lt;P&gt;This solution worked for me.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Feb 2022 14:51:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/585717#M76125</guid>
      <dc:creator>carlkennedy_con</dc:creator>
      <dc:date>2022-02-18T14:51:19Z</dc:date>
    </item>
    <item>
      <title>Re: Errors after Microsoft Azure Add on for Splunk upgrade</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/616119#M77757</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/109095"&gt;@jconger&lt;/a&gt;&amp;nbsp;Thanks for the solution,&lt;/P&gt;&lt;P&gt;Do you think reconfiguring the proxy settings on the Addon after the upgrade will also solve this issues?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Oct 2022 09:54:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/616119#M77757</guid>
      <dc:creator>jabezds</dc:creator>
      <dc:date>2022-10-06T09:54:16Z</dc:date>
    </item>
    <item>
      <title>Re: Errors after Microsoft Azure Add on for Splunk upgrade</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/632406#M78608</link>
      <description>&lt;P&gt;For general interest. This bug is still present in version 1.2.5 of the app. The filenames have changed slightly, the file to which the stanza must be added is now called&amp;nbsp;&lt;STRONG&gt;ta_microsoft_graph_security_add_on_for_splunk_settings.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note that this file is only created by the app if you add a proxy setting, otherwise you will have to manually create it. It is different from the similarly named&amp;nbsp;&lt;STRONG&gt;ta_microsoft_graph_security_add_on_for_splunk_account.conf&amp;nbsp;&lt;/STRONG&gt;configuration file.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2023 20:12:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/632406#M78608</guid>
      <dc:creator>TLepingwell</dc:creator>
      <dc:date>2023-02-27T20:12:11Z</dc:date>
    </item>
    <item>
      <title>Re: Errors after Microsoft Azure Add on for Splunk upgrade</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/712701#M81583</link>
      <description>&lt;P&gt;I'm having a similar issue with the Egnyte Collaborate TA -&amp;nbsp;&lt;A href="https://splunkbase.splunk.com/app/5653" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/5653&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;When trying to use the add-on - I keep getting the following error:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;“01-22-2025 16:45:55.409 +0000 ERROR PersistentScript [1693337 PersistentScriptIo] - From {/opt/splunk/bin/python3.9 /opt/splunk/etc/apps/TA-&lt;/SPAN&gt;&lt;SPAN&gt;egnyte-connect/bin/TA_egnyte_&lt;/SPAN&gt;&lt;SPAN&gt;connect_rh_settings.py persistent}: solnlib.credentials.&lt;/SPAN&gt;&lt;SPAN&gt;CredentialNotExistException: Failed to get password of realm=__REST_CREDENTIAL__#TA-&lt;/SPAN&gt;&lt;SPAN&gt;egnyte-connect#configs/conf-&lt;/SPAN&gt;&lt;SPAN&gt;ta_egnyte_connect_settings, user=proxy.”&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The issue is I'm running Splunk Cloud - and don't have the ability to modify local conf files. Any ideas on how to get this resolved for Slunk Cloud customers?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 14:59:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Errors-after-Microsoft-Azure-Add-on-for-Splunk-upgrade/m-p/712701#M81583</guid>
      <dc:creator>Cerum</dc:creator>
      <dc:date>2025-02-27T14:59:00Z</dc:date>
    </item>
  </channel>
</rss>

