<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ERROR ExecProcessor  cli_common.py&amp;quot;, line 504, in getMgmtUri in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/ERROR-ExecProcessor-cli-common-py-quot-line-504-in-getMgmtUri/m-p/753293#M23111</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;In Splunk Enterprise v10.0.0, the following error is reported in "splunkd.log" ever minute.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;09-18-2025 22:02:00.165 +0000 ERROR ExecProcessor [2560 ExecProcessor] - message from "/cloudmark/splunk/bin/python3.9 /cloudmark/splunk/etc/apps/search/bin/quarantine_files.py" File "/cloudmark/splunk/lib/python3.9/site-packages/splunk/clilib/cli_common.py", line 504, in getMgmtUri&lt;/LI&gt;&lt;LI&gt;09-18-2025 22:03:00.171 +0000 ERROR ExecProcessor [2560 ExecProcessor] - message from "/cloudmark/splunk/bin/python3.9 /cloudmark/splunk/etc/apps/search/bin/quarantine_files.py" File "/cloudmark/splunk/lib/python3.9/site-packages/splunk/clilib/cli_common.py", line 504, in getMgmtUri&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I narrowed to issue to URI "&lt;STRONG&gt;https://[::1]:8089&lt;/STRONG&gt;" written to run file: "&lt;STRONG&gt;/opt/splunk/var/run/splunk/splunkd_uri.txt&lt;/STRONG&gt;".&amp;nbsp; It&amp;nbsp;looks like the python helper script "&lt;STRONG&gt;cli_common.py&lt;/STRONG&gt;" is not properly parsing out the IPv6 address on the colon '&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;:&lt;/STRONG&gt;&lt;/FONT&gt;' delimiter.&amp;nbsp; The temporary fix is to modify the URI to "&lt;STRONG&gt;&lt;A href="https://127.0.0.1:8089" target="_blank" rel="noopener"&gt;https://127.0.0.1:8089&lt;/A&gt;&lt;/STRONG&gt;", which resolves the ERROR.&amp;nbsp; However, after restarting Splunkd, URI "&lt;STRONG&gt;https://[::1]:8089&lt;/STRONG&gt;" is again written to run file&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;"&lt;STRONG&gt;/opt/splunk/var/run/splunk/splunkd_uri.txt&lt;/STRONG&gt;" and the ERROR reoccurs.&lt;/P&gt;&lt;P&gt;Looks like a fix is needed to python script "&lt;STRONG&gt;cli_common.py&lt;/STRONG&gt;" but if the script file is changed, then the Splunk manifest check will complain.&lt;/P&gt;&lt;P&gt;Does anyone know of a permanent fix?&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Sep 2025 22:31:12 GMT</pubDate>
    <dc:creator>ocnsinc</dc:creator>
    <dc:date>2025-09-18T22:31:12Z</dc:date>
    <item>
      <title>ERROR ExecProcessor  cli_common.py", line 504, in getMgmtUri</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/ERROR-ExecProcessor-cli-common-py-quot-line-504-in-getMgmtUri/m-p/753293#M23111</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;In Splunk Enterprise v10.0.0, the following error is reported in "splunkd.log" ever minute.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;09-18-2025 22:02:00.165 +0000 ERROR ExecProcessor [2560 ExecProcessor] - message from "/cloudmark/splunk/bin/python3.9 /cloudmark/splunk/etc/apps/search/bin/quarantine_files.py" File "/cloudmark/splunk/lib/python3.9/site-packages/splunk/clilib/cli_common.py", line 504, in getMgmtUri&lt;/LI&gt;&lt;LI&gt;09-18-2025 22:03:00.171 +0000 ERROR ExecProcessor [2560 ExecProcessor] - message from "/cloudmark/splunk/bin/python3.9 /cloudmark/splunk/etc/apps/search/bin/quarantine_files.py" File "/cloudmark/splunk/lib/python3.9/site-packages/splunk/clilib/cli_common.py", line 504, in getMgmtUri&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I narrowed to issue to URI "&lt;STRONG&gt;https://[::1]:8089&lt;/STRONG&gt;" written to run file: "&lt;STRONG&gt;/opt/splunk/var/run/splunk/splunkd_uri.txt&lt;/STRONG&gt;".&amp;nbsp; It&amp;nbsp;looks like the python helper script "&lt;STRONG&gt;cli_common.py&lt;/STRONG&gt;" is not properly parsing out the IPv6 address on the colon '&lt;FONT color="#FF6600"&gt;&lt;STRONG&gt;:&lt;/STRONG&gt;&lt;/FONT&gt;' delimiter.&amp;nbsp; The temporary fix is to modify the URI to "&lt;STRONG&gt;&lt;A href="https://127.0.0.1:8089" target="_blank" rel="noopener"&gt;https://127.0.0.1:8089&lt;/A&gt;&lt;/STRONG&gt;", which resolves the ERROR.&amp;nbsp; However, after restarting Splunkd, URI "&lt;STRONG&gt;https://[::1]:8089&lt;/STRONG&gt;" is again written to run file&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;"&lt;STRONG&gt;/opt/splunk/var/run/splunk/splunkd_uri.txt&lt;/STRONG&gt;" and the ERROR reoccurs.&lt;/P&gt;&lt;P&gt;Looks like a fix is needed to python script "&lt;STRONG&gt;cli_common.py&lt;/STRONG&gt;" but if the script file is changed, then the Splunk manifest check will complain.&lt;/P&gt;&lt;P&gt;Does anyone know of a permanent fix?&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Sep 2025 22:31:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/ERROR-ExecProcessor-cli-common-py-quot-line-504-in-getMgmtUri/m-p/753293#M23111</guid>
      <dc:creator>ocnsinc</dc:creator>
      <dc:date>2025-09-18T22:31:12Z</dc:date>
    </item>
    <item>
      <title>Re: ERROR ExecProcessor  cli_common.py", line 504, in getMgmtUri</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/ERROR-ExecProcessor-cli-common-py-quot-line-504-in-getMgmtUri/m-p/753326#M23112</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/239346"&gt;@ocnsinc&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As this is an issue with a built-in script you are right that the manifest will complain about the change and also it will be overwritten in the future if you upgrade. I think the best thing to do raise with Splunk Support and hopefully they will raise a bug and get it resolved in a future release.&lt;/P&gt;&lt;P&gt;Head over to&amp;nbsp;&lt;A href="https://www.splunk.com/support" target="_blank"&gt;https://www.splunk.com/support&lt;/A&gt;&amp;nbsp;to raise a support case.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2025 11:39:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/ERROR-ExecProcessor-cli-common-py-quot-line-504-in-getMgmtUri/m-p/753326#M23112</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-09-19T11:39:15Z</dc:date>
    </item>
  </channel>
</rss>

