<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TA-ms-loganalytics data ingestion issue for few sourcetypes in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/556229#M6144</link>
    <description>&lt;P&gt;I'm also having the same error, did you guys able to fix it?&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199197"&gt;@jkat54&lt;/a&gt;&amp;nbsp;can you please&amp;nbsp; help us here?&lt;/P&gt;</description>
    <pubDate>Thu, 17 Jun 2021 19:12:07 GMT</pubDate>
    <dc:creator>raja_mta</dc:creator>
    <dc:date>2021-06-17T19:12:07Z</dc:date>
    <item>
      <title>TA-ms-loganalytics data ingestion issue for few sourcetypes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/543536#M5258</link>
      <description>&lt;P&gt;hi&lt;/P&gt;&lt;P&gt;i am having issues where some of the sourcetypes are not getting data in splunk from LA,&amp;nbsp; upon checking some logs i can see below :&lt;/P&gt;&lt;P&gt;2021-03-11 13:07:39,577 ERROR pid=13031 tid=MainThread file=base_modinput.py:log_error:307 | OMSInputName="MyInput" status="400" step="Post Query" response="{"error":{"message":"Response size too large","code":"ResponseSizeError","correlationId":"XXX","innererror":{"code":"ResponseSizeError","message":"Maximum response size of 67108864 bytes exceeded. Actual response Size is 73664723 bytes."}}}"&lt;BR /&gt;2021-03-11 13:07:39,577 ERROR pid=13031 tid=MainThread file=base_modinput.py:log_error:307 | Get error when collecting events.&lt;BR /&gt;Traceback (most recent call last):&lt;BR /&gt;File "$splunkhome$/etc/apps/TA-ms-loganalytics/bin/ta_ms_loganalytics/modinput_wrapper/base_modinput.py", line 127, in stream_events&lt;BR /&gt;self.collect_events(ew)&lt;BR /&gt;File "$splunkhome$/etc/apps/TA-ms-loganalytics/bin/log_analytics.py", line 96, in collect_events&lt;BR /&gt;input_module.collect_events(self, ew)&lt;BR /&gt;File "$splunkhome$/etc/apps/TA-ms-loganalytics/bin/input_module_log_analytics.py", line 86, in collect_events&lt;BR /&gt;for i in range(len(data["tables"][0]["rows"])):&lt;BR /&gt;UnboundLocalError: local variable 'data' referenced before assignment&lt;/P&gt;&lt;P&gt;2021-03-11 13:08:18,608 ERROR pid=13216 tid=MainThread file=base_modinput.py:log_error:307 | OMSInputName="MyInput2" status="400" step="Post Query" response="{"error":{"message":"Response size too large","code":"ResponseSizeError","correlationId":"XXX","innererror":{"code":"ResponseSizeError","message":"Maximum response size of 67108864 bytes exceeded. Actual response Size is 73136457 bytes."}}}"&lt;BR /&gt;2021-03-11 13:08:18,608 ERROR pid=13216 tid=MainThread file=base_modinput.py:log_error:307 | Get error when collecting events.&lt;BR /&gt;Traceback (most recent call last):&lt;BR /&gt;File "$splunkhome$/etc/apps/TA-ms-loganalytics/bin/ta_ms_loganalytics/modinput_wrapper/base_modinput.py", line 127, in stream_events&lt;BR /&gt;self.collect_events(ew)&lt;BR /&gt;File "$splunkhome$/etc/apps/TA-ms-loganalytics/bin/log_analytics.py", line 96, in collect_events&lt;BR /&gt;input_module.collect_events(self, ew)&lt;BR /&gt;File "$splunkhome$/etc/apps/TA-ms-loganalytics/bin/input_module_log_analytics.py", line 86, in collect_events&lt;BR /&gt;for i in range(len(data["tables"][0]["rows"])):&lt;BR /&gt;UnboundLocalError: local variable 'data' referenced before assignment&lt;/P&gt;&lt;P&gt;Am i hitting any limitation ? if so, any way to overcome this ?&lt;/P&gt;&lt;P&gt;any suggestions appreciated...&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199197"&gt;@jkat54&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 Mar 2021 12:41:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/543536#M5258</guid>
      <dc:creator>jaihingorani</dc:creator>
      <dc:date>2021-03-12T12:41:41Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics data ingestion issue for few sourcetypes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/543964#M5288</link>
      <description>&lt;P&gt;Even I am facing same issue.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;response="{"error":{"message":"Response size too large","code":"ResponseSizeError","correlationId":"XXX","innererror":&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Mar 2021 09:01:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/543964#M5288</guid>
      <dc:creator>sahilyahiya</dc:creator>
      <dc:date>2021-03-16T09:01:00Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics data ingestion issue for few sourcetypes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/544131#M5299</link>
      <description>&lt;P&gt;Hi I'm getting the exact same issue, it started with one workspace a couple of weeks ago now i have 5 of the 6 of them faulting with the error.&lt;/P&gt;&lt;P&gt;I believe there is a 67 MB limit on the response size.&lt;/P&gt;&lt;P&gt;I've trimmed back the time from 300 seconds down to 120 seconds and still get the same error.&lt;/P&gt;&lt;P&gt;We're using generic "search *" queries to get all the tables,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm meeting with devops this afternoon to go over it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 08:35:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/544131#M5299</guid>
      <dc:creator>JimboSlice</dc:creator>
      <dc:date>2021-03-17T08:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics data ingestion issue for few sourcetypes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/544132#M5300</link>
      <description>&lt;P&gt;exactly... reducing the interval doesn't help, as its some kind of response limit it is hitting&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232415"&gt;@JimboSlice&lt;/a&gt; do comment here if you are able to trace it out anything... much appreciated!!&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 08:40:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/544132#M5300</guid>
      <dc:creator>jaihingorani</dc:creator>
      <dc:date>2021-03-17T08:40:49Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics data ingestion issue for few sourcetypes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/544136#M5302</link>
      <description>&lt;P&gt;Oh yeah i sure will, i think if devops confirm that nothing extra has been added to the LAWS (tables or bulks in to the tables) then we will open a support ticket with azure.&lt;/P&gt;&lt;P&gt;There doesn't seem to be any buffer settings under the hood and from what ive read elsewhere there is a 67MB limit on the azure side, devops originally told me this a few weeks ago and ive seen this on the web on a powerBI forum, but why this is suddenly happening to us all at the same time arouses suspicion.&lt;/P&gt;&lt;P&gt;Azure logs are the worst logs on the planet, constant issues (also event hubs).&lt;/P&gt;</description>
      <pubDate>Wed, 17 Mar 2021 09:04:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/544136#M5302</guid>
      <dc:creator>JimboSlice</dc:creator>
      <dc:date>2021-03-17T09:04:26Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics data ingestion issue for few sourcetypes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/544302#M5317</link>
      <description>&lt;P&gt;We have sent this on to our azure support team to get to the bottom of it, it appeared yesterday that when running queries in the management console for LAWS, this same error came up and we think something has changed on the azure side.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 08:42:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/544302#M5317</guid>
      <dc:creator>JimboSlice</dc:creator>
      <dc:date>2021-03-18T08:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics data ingestion issue for few sourcetypes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/544315#M5319</link>
      <description>&lt;P&gt;right, noticed the same while querying at LA, will reach out to our counterparts and see, will keep posted.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Mar 2021 11:15:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/544315#M5319</guid>
      <dc:creator>jaihingorani</dc:creator>
      <dc:date>2021-03-18T11:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics data ingestion issue for few sourcetypes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/556229#M6144</link>
      <description>&lt;P&gt;I'm also having the same error, did you guys able to fix it?&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199197"&gt;@jkat54&lt;/a&gt;&amp;nbsp;can you please&amp;nbsp; help us here?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jun 2021 19:12:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/556229#M6144</guid>
      <dc:creator>raja_mta</dc:creator>
      <dc:date>2021-06-17T19:12:07Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics data ingestion issue for few sourcetypes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/556255#M6147</link>
      <description>&lt;P&gt;Hey first off, nice work everyone!&lt;/P&gt;&lt;P&gt;I'd love to help but I don't have a lab to test this in anymore. &amp;nbsp;Certainly does sound something changed on their end, but without a lab, I can't develop a solution.&lt;/P&gt;&lt;P&gt;You can use the contact the developer button on splunkbase to email me and we can discuss your options if you like.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jun 2021 01:03:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/556255#M6147</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2021-06-18T01:03:04Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics data ingestion issue for few sourcetypes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/556282#M6150</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/235550"&gt;@raja_mta&lt;/a&gt;&amp;nbsp;, i was able to make it work by increasing the interval for one of the input, as interval is set as 300 seconds for most of my inputs, however since few weeks i am again facing the same issue with another input, but increasing the interval is not helping now, will let you know if i am able to make it work by any other way.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Jun 2021 05:59:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/556282#M6150</guid>
      <dc:creator>jaihingorani</dc:creator>
      <dc:date>2021-06-18T05:59:18Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics data ingestion issue for few sourcetypes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/573211#M10552</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199197"&gt;@jkat54&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;I sent an email to you on this. can you please respond.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 17:40:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/573211#M10552</guid>
      <dc:creator>raja_mta</dc:creator>
      <dc:date>2021-11-01T17:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics data ingestion issue for few sourcetypes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/577085#M10871</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232415"&gt;@JimboSlice&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;By any chance do you have any update from Azure side?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Dec 2021 15:09:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/577085#M10871</guid>
      <dc:creator>raja_mta</dc:creator>
      <dc:date>2021-12-02T15:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics data ingestion issue for few sourcetypes</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/578211#M10948</link>
      <description>&lt;P&gt;here goes another input, but it got stopped with different limit.&amp;nbsp;&lt;/P&gt;&lt;P&gt;"innererror":{"code":"ResponseSizeError","message":"Maximum response size of 100000000 bytes exceeded. Actual response Size is 103052502 bytes."&lt;/P&gt;&lt;P&gt;now the limit says it has exceeded 100MB, can anyone explain ?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Dec 2021 13:46:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/TA-ms-loganalytics-data-ingestion-issue-for-few-sourcetypes/m-p/578211#M10948</guid>
      <dc:creator>jaihingorani</dc:creator>
      <dc:date>2021-12-13T13:46:20Z</dc:date>
    </item>
  </channel>
</rss>

