<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Error messages using Google Cloud Platform Add-on in Splunk Dev</title>
    <link>https://community.splunk.com/t5/Splunk-Dev/Error-messages-using-Google-Cloud-Platform-Add-on/m-p/288020#M3572</link>
    <description>&lt;P&gt;I have configured the add-on for Google Cloud Platform and verified that pub/sub messages are being written to the pub/sub topic from GCP and that messages are successfully being pulled from the Splunk subscription. No GCP logs are appearing in Splunk. The error seems to be internal to Splunk. I have captured error messages from 2 different relevant logs below.&lt;/P&gt;

&lt;P&gt;The following log messages are repeated in the /opt/splunk/var/log/splunk/splunk_ta_google_pubsub_util.log&lt;/P&gt;

&lt;P&gt;2018-01-04 18:59:53,807 ERROR pid=470 tid=Thread-2 file=event_writer.py:write_events:268 | Failed to post events to HEC_URI=&lt;A href="https://127.0.0.1:8088/services/collector" target="_blank"&gt;https://127.0.0.1:8088/services/collector&lt;/A&gt;, error_code=400, reason={"text":"Invalid data format","code":6,"invalid-event-number":0}&lt;BR /&gt;
2018-01-04 18:59:54,591 ERROR pid=470 tid=Thread-2 file=event_writer.py:write_events:268 | Failed to post events to HEC_URI=&lt;A href="https://127.0.0.1:8088/services/collector" target="_blank"&gt;https://127.0.0.1:8088/services/collector&lt;/A&gt;, error_code=400, reason={"text":"Invalid data format","code":6,"invalid-event-number":0}&lt;/P&gt;

&lt;P&gt;The following log messages are repeated in the /opt/splunk/var/log/splunk/splunk_ta_google_pubsub_main.log&lt;/P&gt;

&lt;P&gt;2018-01-04 19:59:23,387 ERROR pid=470 tid=Thread-2 file=google_pubsub_data_loader.py:index_data:70 | Failed to collect data for project=[MY_PROJECT]t, subscription=[MY_SUBSCRIPTION], error=Traceback (most recent call last):&lt;BR /&gt;
  File "/opt/splunk/etc/apps/Splunk_TA_google-cloudplatform/bin/pubsub_mod/google_pubsub_data_loader.py", line 64, in index_data&lt;BR /&gt;
    self._do_safe_index()&lt;BR /&gt;
  File "/opt/splunk/etc/apps/Splunk_TA_google-cloudplatform/bin/pubsub_mod/google_pubsub_data_loader.py", line 86, in _do_safe_index&lt;BR /&gt;
    for msgs in sub.pull_messages():&lt;BR /&gt;
  File "/opt/splunk/etc/apps/Splunk_TA_google-cloudplatform/bin/google_wrapper/pubsub_wrapper.py", line 85, in pull_messages&lt;BR /&gt;
    for message in messages:&lt;BR /&gt;
TypeError: 'NoneType' object is not iterable&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 17:29:33 GMT</pubDate>
    <dc:creator>c2bi</dc:creator>
    <dc:date>2020-09-29T17:29:33Z</dc:date>
    <item>
      <title>Error messages using Google Cloud Platform Add-on</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-messages-using-Google-Cloud-Platform-Add-on/m-p/288020#M3572</link>
      <description>&lt;P&gt;I have configured the add-on for Google Cloud Platform and verified that pub/sub messages are being written to the pub/sub topic from GCP and that messages are successfully being pulled from the Splunk subscription. No GCP logs are appearing in Splunk. The error seems to be internal to Splunk. I have captured error messages from 2 different relevant logs below.&lt;/P&gt;

&lt;P&gt;The following log messages are repeated in the /opt/splunk/var/log/splunk/splunk_ta_google_pubsub_util.log&lt;/P&gt;

&lt;P&gt;2018-01-04 18:59:53,807 ERROR pid=470 tid=Thread-2 file=event_writer.py:write_events:268 | Failed to post events to HEC_URI=&lt;A href="https://127.0.0.1:8088/services/collector" target="_blank"&gt;https://127.0.0.1:8088/services/collector&lt;/A&gt;, error_code=400, reason={"text":"Invalid data format","code":6,"invalid-event-number":0}&lt;BR /&gt;
2018-01-04 18:59:54,591 ERROR pid=470 tid=Thread-2 file=event_writer.py:write_events:268 | Failed to post events to HEC_URI=&lt;A href="https://127.0.0.1:8088/services/collector" target="_blank"&gt;https://127.0.0.1:8088/services/collector&lt;/A&gt;, error_code=400, reason={"text":"Invalid data format","code":6,"invalid-event-number":0}&lt;/P&gt;

&lt;P&gt;The following log messages are repeated in the /opt/splunk/var/log/splunk/splunk_ta_google_pubsub_main.log&lt;/P&gt;

&lt;P&gt;2018-01-04 19:59:23,387 ERROR pid=470 tid=Thread-2 file=google_pubsub_data_loader.py:index_data:70 | Failed to collect data for project=[MY_PROJECT]t, subscription=[MY_SUBSCRIPTION], error=Traceback (most recent call last):&lt;BR /&gt;
  File "/opt/splunk/etc/apps/Splunk_TA_google-cloudplatform/bin/pubsub_mod/google_pubsub_data_loader.py", line 64, in index_data&lt;BR /&gt;
    self._do_safe_index()&lt;BR /&gt;
  File "/opt/splunk/etc/apps/Splunk_TA_google-cloudplatform/bin/pubsub_mod/google_pubsub_data_loader.py", line 86, in _do_safe_index&lt;BR /&gt;
    for msgs in sub.pull_messages():&lt;BR /&gt;
  File "/opt/splunk/etc/apps/Splunk_TA_google-cloudplatform/bin/google_wrapper/pubsub_wrapper.py", line 85, in pull_messages&lt;BR /&gt;
    for message in messages:&lt;BR /&gt;
TypeError: 'NoneType' object is not iterable&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:29:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-messages-using-Google-Cloud-Platform-Add-on/m-p/288020#M3572</guid>
      <dc:creator>c2bi</dc:creator>
      <dc:date>2020-09-29T17:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: Error messages using Google Cloud Platform Add-on</title>
      <link>https://community.splunk.com/t5/Splunk-Dev/Error-messages-using-Google-Cloud-Platform-Add-on/m-p/288021#M3573</link>
      <description>&lt;P&gt;This sounds similar to an issue experienced when attempting to use the add-on with version 7.x of Splunk.  I don't see the version of Splunk you are using listed in your question..but if you are using a version newer then 6.5 (the last supported version listed on splunk base for this particular add-on), you might try the below fix. &lt;/P&gt;

&lt;P&gt;If google_global_settings.conf does not already exist in the local directory, create the file, if not, add the below stanza to it, then restart your instance.  The conf file path would be: &lt;/P&gt;

&lt;P&gt;$SPLUNK_HOME/etc/apps/Splunk_TA_googlecloudplatform/local/google_global_settings.conf&lt;/P&gt;

&lt;P&gt;And the stanza:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[global_settings]
 use_hec = 0
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 17:33:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Dev/Error-messages-using-Google-Cloud-Platform-Add-on/m-p/288021#M3573</guid>
      <dc:creator>amarrazzo</dc:creator>
      <dc:date>2020-09-29T17:33:51Z</dc:date>
    </item>
  </channel>
</rss>

