<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: TA-ms-loganalytics stops sending data in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/593462#M10537</link>
    <description>&lt;P&gt;you can reduce the amount of data the query returns by adjusting the query.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Apr 2022 13:50:01 GMT</pubDate>
    <dc:creator>jkat54</dc:creator>
    <dc:date>2022-04-12T13:50:01Z</dc:date>
    <item>
      <title>Why does TA-ms-loganalytics stops sending data?</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/593128#M10532</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;hope someone can help here.&lt;/P&gt;
&lt;P&gt;ta-ms-loganalytics have suddenly stopped working, i can see below type of errors being logged about the modular inputs&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class=""&gt;ERROR&lt;/SPAN&gt; &lt;SPAN class=""&gt;ModularInputs&lt;/SPAN&gt; &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;Unable&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;initialize&lt;/SPAN&gt; &lt;SPAN class=""&gt;modular&lt;/SPAN&gt; &lt;SPAN class=""&gt;input&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;log_analytics&lt;/SPAN&gt;&lt;SPAN&gt;" &lt;/SPAN&gt;&lt;SPAN class=""&gt;defined&lt;/SPAN&gt; &lt;SPAN class=""&gt;inside&lt;/SPAN&gt; &lt;SPAN class=""&gt;the&lt;/SPAN&gt; &lt;SPAN class=""&gt;app&lt;/SPAN&gt;&lt;SPAN&gt; "&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;TA-ms-loganalytics&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Introspecting&lt;/SPAN&gt; &lt;SPAN class=""&gt;scheme=log_analytics:&lt;/SPAN&gt; &lt;SPAN class=""&gt;script&lt;/SPAN&gt; &lt;SPAN class=""&gt;running&lt;/SPAN&gt; &lt;SPAN class=""&gt;failed&lt;/SPAN&gt;&lt;SPAN&gt; (&lt;/SPAN&gt;&lt;SPAN class=""&gt;killed&lt;/SPAN&gt; &lt;SPAN class=""&gt;by&lt;/SPAN&gt; &lt;SPAN class=""&gt;signal&lt;/SPAN&gt; &lt;SPAN class=""&gt;9:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Killed&lt;/SPAN&gt;&lt;SPAN&gt;).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;SPAN class=""&gt;raise&lt;/SPAN&gt; &lt;SPAN class=""&gt;ConnectionError&lt;/SPAN&gt;(&lt;SPAN class=""&gt;e&lt;/SPAN&gt;, &lt;SPAN class=""&gt;request=request&lt;/SPAN&gt;)&lt;SPAN class=""&gt;\nConnectionError:&lt;/SPAN&gt; &lt;SPAN class=""&gt;HTTPSConnectionPool&lt;/SPAN&gt;(&lt;SPAN class=""&gt;host=&lt;/SPAN&gt;'&lt;SPAN class=""&gt;127.0.0.1&lt;/SPAN&gt;', &lt;SPAN class=""&gt;port=8089&lt;/SPAN&gt;)&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Max&lt;/SPAN&gt; &lt;SPAN class=""&gt;retries&lt;/SPAN&gt; &lt;SPAN class=""&gt;exceeded&lt;/SPAN&gt; &lt;SPAN class=""&gt;with&lt;/SPAN&gt; &lt;SPAN class=""&gt;url:&lt;/SPAN&gt; &lt;SPAN class=""&gt;/servicesNS/nobody/TA-ms-loganalytics/data/inputs/log_analytics&lt;/SPAN&gt;?&lt;SPAN class=""&gt;count=0&lt;/SPAN&gt;&amp;amp;&lt;SPAN class=""&gt;output_mode=json&lt;/SPAN&gt; (&lt;SPAN class=""&gt;Caused&lt;/SPAN&gt; &lt;SPAN class=""&gt;by&lt;/SPAN&gt; &lt;SPAN class=""&gt;NewConnectionError&lt;/SPAN&gt;('&amp;lt;&lt;SPAN class=""&gt;solnlib.packages.requests.packages.urllib3.connection.VerifiedHTTPSConnection&lt;/SPAN&gt; &lt;SPAN class=""&gt;object&lt;/SPAN&gt; &lt;SPAN class=""&gt;at&lt;/SPAN&gt; &lt;SPAN class=""&gt;0x7f118318e610&lt;/SPAN&gt;&amp;gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Failed&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt; &lt;SPAN class=""&gt;establish&lt;/SPAN&gt; &lt;SPAN class=""&gt;a&lt;/SPAN&gt; &lt;SPAN class=""&gt;new&lt;/SPAN&gt; &lt;SPAN class=""&gt;connection:&lt;/SPAN&gt; [&lt;SPAN class=""&gt;Errno&lt;/SPAN&gt; &lt;SPAN class=""&gt;111&lt;/SPAN&gt;] &lt;SPAN class=""&gt;Connection&lt;/SPAN&gt; &lt;SPAN class=""&gt;refused&lt;/SPAN&gt;',))&lt;SPAN class=""&gt;\n&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;any help much appreciated.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 15:48:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/593128#M10532</guid>
      <dc:creator>jaihingorani</dc:creator>
      <dc:date>2022-04-19T15:48:13Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics stops sending data</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/593129#M10533</link>
      <description>&lt;P&gt;It says it's not able to establish a connection. &amp;nbsp;Did firewall rules change? &amp;nbsp;Can you curl the azure api from the host?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 15:22:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/593129#M10533</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2022-04-08T15:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics stops sending data</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/593130#M10534</link>
      <description>&lt;P&gt;Thank You &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199197"&gt;@jkat54&lt;/a&gt;&amp;nbsp; for responding, we checked with our network teams, there were no changes related to firewalls, we have restarted the splunk services, and we dont see these connection errors anymore, its now logging "&lt;SPAN class=""&gt;ERROR&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;ModularInputs&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Unable&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;to&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;initialize&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;modular&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;input&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;log_analytics&lt;/SPAN&gt;&lt;SPAN&gt;"&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;defined&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;inside&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;the&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;app&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;TA-ms-loganalytics&lt;/SPAN&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;SPAN class=""&gt;:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Introspecting&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;scheme=log_analytics:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;script&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;running&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;failed&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;(&lt;/SPAN&gt;&lt;SPAN class=""&gt;killed&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;by&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;signal&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;9:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;Killed&lt;/SPAN&gt;&lt;SPAN&gt;)."&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Apr 2022 15:25:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/593130#M10534</guid>
      <dc:creator>jaihingorani</dc:creator>
      <dc:date>2022-04-08T15:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics stops sending data</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/593131#M10535</link>
      <description>curl the azure API -&amp;gt; can you give an example how can i check this ?</description>
      <pubDate>Fri, 08 Apr 2022 15:28:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/593131#M10535</guid>
      <dc:creator>jaihingorani</dc:creator>
      <dc:date>2022-04-08T15:28:33Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics stops sending data</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/593454#M10536</link>
      <description>&lt;P&gt;Hello again&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199197"&gt;@jkat54&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it turned out to be some issues at the OS end, as the CLI was responding slow as well, the logs started to come in post the server reboot. But few of the sources are having the errors as below:&lt;/P&gt;&lt;P&gt;2022-04-12 13:22:23,902 ERROR pid=26000 tid=MainThread file=base_modinput.py:log_error:307 | OMSInputName="My_Diagnostics" status="400" step="Post Query" response="{"error":{"message":"Response size too large","code":"ResponseSizeError","correlationId":"&amp;lt;myID&amp;gt;","innererror":{"code":"ResponseSizeError","message":"Maximum response size of 100000000 bytes exceeded. Actual response Size is 107148567 bytes."}}}"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you suggest if this is something which we can tweak the values for ?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 12:54:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/593454#M10536</guid>
      <dc:creator>jaihingorani</dc:creator>
      <dc:date>2022-04-12T12:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics stops sending data</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/593462#M10537</link>
      <description>&lt;P&gt;you can reduce the amount of data the query returns by adjusting the query.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 13:50:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/593462#M10537</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2022-04-12T13:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics stops sending data</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/593463#M10538</link>
      <description>&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/rest/api/loganalytics/dataaccess/query/get" target="_blank"&gt;https://docs.microsoft.com/en-us/rest/api/loganalytics/dataaccess/query/get&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Apr 2022 13:51:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/593463#M10538</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2022-04-12T13:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics stops sending data</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/594292#M10539</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199197"&gt;@jkat54&lt;/a&gt;&amp;nbsp;, we have been considering this option, but turns out that our internal teams requires all the data which was being pulled. Is there any way we can increase this limit instead ?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 14:36:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/594292#M10539</guid>
      <dc:creator>jaihingorani</dc:creator>
      <dc:date>2022-04-19T14:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics stops sending data</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/594295#M10540</link>
      <description>&lt;P&gt;I'm not super familiar with log analytics queries.&lt;/P&gt;&lt;P&gt;can you limit the time frame of the query?&lt;/P&gt;&lt;P&gt;in splunk you have earliest, latest, etc. &amp;nbsp;can you grab half the data with one query and the other half with another?&lt;/P&gt;</description>
      <pubDate>Tue, 19 Apr 2022 15:07:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/594295#M10540</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2022-04-19T15:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics stops sending data</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/594641#M10541</link>
      <description>&lt;P&gt;but the inputs are running at every 10minutes of interval, setting the timestamp in the query will not work, because if we do so it will pull the same timeframe of data every 10minutes. is there any way to increase the response size in the TA-ms-loganalytics add on ?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 11:09:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/594641#M10541</guid>
      <dc:creator>jaihingorani</dc:creator>
      <dc:date>2022-04-21T11:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics stops sending data</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/594646#M10542</link>
      <description>&lt;P&gt;Does the query pull all the data every 10 minutes? &amp;nbsp;Instead of getting data for last 10m?&lt;/P&gt;&lt;P&gt;If you run it every 5 minutes will it help?&lt;/P&gt;&lt;P&gt;Please note the size limitation is not from my app, it's the limit on the azure API. &amp;nbsp;You have to reduce the results your query returns or it will always have this error.&lt;/P&gt;&lt;P&gt;you should appeal to azure support if can't figure out how to reduce the size of your query, and can't increase the limit on the API.&lt;/P&gt;&lt;P&gt;There's literally nothing I can do on my end to fix this issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 11:50:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/594646#M10542</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2022-04-21T11:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics stops sending data</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/594650#M10543</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199197"&gt;@jkat54&lt;/a&gt;&amp;nbsp;, and understood its the API limit.&amp;nbsp;&lt;/P&gt;&lt;P&gt;the interval is changed to 5 minutes, and its still the same. should the value of&amp;nbsp;event_delay_lag_time = 15 also need to be reduced ?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 12:04:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/594650#M10543</guid>
      <dc:creator>jaihingorani</dc:creator>
      <dc:date>2022-04-21T12:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics stops sending data</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/594653#M10544</link>
      <description>&lt;P&gt;Hear me out...&lt;/P&gt;&lt;P&gt;if you run a query that generates more events than the limit, it will not matter how often or even when you run that query.&lt;/P&gt;&lt;P&gt;so what you have to do, is change your query or increase the limit. &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 12:09:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/594653#M10544</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2022-04-21T12:09:39Z</dc:date>
    </item>
    <item>
      <title>Re: TA-ms-loganalytics stops sending data</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/594655#M10545</link>
      <description>&lt;P&gt;Thanks again, we will explore the possibilities to change the query.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2022 12:15:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Why-does-TA-ms-loganalytics-stops-sending-data/m-p/594655#M10545</guid>
      <dc:creator>jaihingorani</dc:creator>
      <dc:date>2022-04-21T12:15:29Z</dc:date>
    </item>
  </channel>
</rss>

