<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Add-on for Microsoft cloud services in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-cloud-services/m-p/565532#M100618</link>
    <description>&lt;P class="lia-align-left"&gt;&lt;FONT face="book antiqua,palatino"&gt;Wondering if someone have resolved this issue already as I am having same issue.&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Sep 2021 17:41:07 GMT</pubDate>
    <dc:creator>cdahal</dc:creator>
    <dc:date>2021-09-01T17:41:07Z</dc:date>
    <item>
      <title>Splunk Add-on for Microsoft cloud services</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-cloud-services/m-p/553722#M91801</link>
      <description>&lt;P&gt;Guys, could you please shed some light here?&lt;/P&gt;&lt;P&gt;I have configured azure api management to stream events to event hub and Spunk add-on to connect to event hub. I am receiving the below error.&lt;/P&gt;&lt;P&gt;I have given the Azure Event hub data receiver role to the IAM account used in the integratiion.&lt;/P&gt;&lt;DIV class="raw-event normal  wrap "&gt;&lt;SPAN class="t"&gt;2021-05-31&lt;/SPAN&gt; &lt;SPAN class="t"&gt;14:58:33&lt;/SPAN&gt;,&lt;SPAN class="t"&gt;763&lt;/SPAN&gt; &lt;SPAN class="t"&gt;level=ERROR&lt;/SPAN&gt; &lt;SPAN class="t"&gt;pid=9469&lt;/SPAN&gt; &lt;SPAN class="t"&gt;tid=MainThread&lt;/SPAN&gt; &lt;SPAN class="t"&gt;logger=__main__&lt;/SPAN&gt; &lt;SPAN class="t"&gt;pos=utils.py:wrapper:72&lt;/SPAN&gt; | &lt;SPAN class="t"&gt;datainput=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;myapim&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;start_time=1622473113&lt;/SPAN&gt; | &lt;SPAN class="t"&gt;message=&lt;/SPAN&gt;"&lt;SPAN class="t"&gt;Data&lt;/SPAN&gt; &lt;SPAN class="t"&gt;input&lt;/SPAN&gt; &lt;SPAN class="t"&gt;was&lt;/SPAN&gt; &lt;SPAN class="t"&gt;interrupted&lt;/SPAN&gt; &lt;SPAN class="t"&gt;by&lt;/SPAN&gt; &lt;SPAN class="t"&gt;an&lt;/SPAN&gt; &lt;SPAN class="t"&gt;unhandled&lt;/SPAN&gt; &lt;SPAN class="t"&gt;exception.&lt;/SPAN&gt;" &lt;SPAN class="t"&gt;Traceback&lt;/SPAN&gt; (&lt;SPAN class="t"&gt;most&lt;/SPAN&gt; &lt;SPAN class="t"&gt;recent&lt;/SPAN&gt; &lt;SPAN class="t"&gt;call&lt;/SPAN&gt; &lt;SPAN class="t"&gt;last&lt;/SPAN&gt;)&lt;SPAN class="t"&gt;:&lt;/SPAN&gt; &lt;SPAN class="t"&gt;File&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;/opt/splunk/etc/apps/Splunk_TA_microsoft-cloudservices/lib/splunksdc/utils.py&lt;/SPAN&gt;", &lt;SPAN class="t"&gt;line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;70&lt;/SPAN&gt;, &lt;SPAN class="t"&gt;in&lt;/SPAN&gt; &lt;SPAN class="t"&gt;wrapper&lt;/SPAN&gt; &lt;SPAN class="t"&gt;return&lt;/SPAN&gt; &lt;SPAN class="t"&gt;func&lt;/SPAN&gt;(*&lt;SPAN class="t"&gt;args&lt;/SPAN&gt;, **&lt;SPAN class="t"&gt;kwargs&lt;/SPAN&gt;) &lt;SPAN class="t"&gt;File&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;/opt/splunk/etc/apps/Splunk_TA_microsoft-cloudservices/bin/mscs_azure_event_hub.py&lt;/SPAN&gt;", &lt;SPAN class="t"&gt;line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;636&lt;/SPAN&gt;, &lt;SPAN class="t"&gt;in&lt;/SPAN&gt; &lt;SPAN class="t"&gt;run&lt;/SPAN&gt; &lt;SPAN class="t"&gt;consumer&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt; &lt;SPAN class="t"&gt;self._create_event_hub_consumer&lt;/SPAN&gt;(&lt;SPAN class="t"&gt;workspace&lt;/SPAN&gt;, &lt;SPAN class="t"&gt;credential&lt;/SPAN&gt;, &lt;SPAN class="t"&gt;proxy&lt;/SPAN&gt;) &lt;SPAN class="t"&gt;File&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;/opt/splunk/etc/apps/Splunk_TA_microsoft-cloudservices/bin/mscs_azure_event_hub.py&lt;/SPAN&gt;", &lt;SPAN class="t"&gt;line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;592&lt;/SPAN&gt;, &lt;SPAN class="t"&gt;in&lt;/SPAN&gt; &lt;SPAN class="t"&gt;_create_event_hub_consumer&lt;/SPAN&gt; &lt;SPAN class="t"&gt;args.consumer_group&lt;/SPAN&gt;, &lt;SPAN class="t"&gt;File&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;/opt/splunk/etc/apps/Splunk_TA_microsoft-cloudservices/bin/mscs_azure_event_hub.py&lt;/SPAN&gt;", &lt;SPAN class="t"&gt;line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;215&lt;/SPAN&gt;, &lt;SPAN class="t"&gt;in&lt;/SPAN&gt; &lt;SPAN class="t"&gt;open&lt;/SPAN&gt; &lt;SPAN class="t"&gt;checkpoint&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt; &lt;SPAN class="t"&gt;SharedLocalCheckpoint&lt;/SPAN&gt;(&lt;SPAN class="t"&gt;fullname&lt;/SPAN&gt;) &lt;SPAN class="t"&gt;File&lt;/SPAN&gt; "&lt;SPAN class="t"&gt;/opt/splunk/etc/apps/Splunk_TA_microsoft-cloudservices/bin/mscs_azure_event_hub.py&lt;/SPAN&gt;", &lt;SPAN class="t"&gt;line&lt;/SPAN&gt; &lt;SPAN class="t"&gt;87&lt;/SPAN&gt;, &lt;SPAN class="t"&gt;in&lt;/SPAN&gt; &lt;SPAN class="t"&gt;__init__&lt;/SPAN&gt; &lt;SPAN class="t"&gt;self._fd&lt;/SPAN&gt; &lt;SPAN class="t"&gt;=&lt;/SPAN&gt; &lt;SPAN class="t"&gt;os.open&lt;/SPAN&gt;(&lt;SPAN class="t"&gt;fullname&lt;/SPAN&gt;, &lt;SPAN class="t"&gt;os.O_RDWR&lt;/SPAN&gt; | &lt;SPAN class="t"&gt;os.O_CREAT&lt;/SPAN&gt;) &lt;SPAN class="t"&gt;FileNotFoundError:&lt;/SPAN&gt; [&lt;SPAN class="t"&gt;Errno&lt;/SPAN&gt; &lt;SPAN class="t"&gt;2&lt;/SPAN&gt;] &lt;SPAN class="t"&gt;No&lt;/SPAN&gt; &lt;SPAN class="t"&gt;such&lt;/SPAN&gt; &lt;SPAN class="t"&gt;file&lt;/SPAN&gt; &lt;SPAN class="t"&gt;or&lt;/SPAN&gt; &lt;SPAN class="t"&gt;directory:&lt;/SPAN&gt; '&lt;SPAN class="t"&gt;/opt/splunk/var/lib/splunk/modinputs/mscs_azure_event_hub/Endpoint=sb://mynamespace.servicebus.windows.net/&lt;/SPAN&gt;;&lt;SPAN class="t"&gt;SharedAccessKeyName=RootManageSharedAccessKey&lt;/SPAN&gt;;&lt;SPAN class="t"&gt;SharedAccessKey=xxxxxxxxx&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-myeventhub-myconsumergroup.v1.ckpt'&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="raw-event normal  wrap "&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 31 May 2021 15:06:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-cloud-services/m-p/553722#M91801</guid>
      <dc:creator>Knightrider1234</dc:creator>
      <dc:date>2021-05-31T15:06:25Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft cloud services</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-cloud-services/m-p/557084#M92182</link>
      <description>&lt;P&gt;Hello ... Did you ever get this resolved? I'm running into the same issue. It seems to have something to do with the&amp;nbsp;&lt;SPAN class="s1"&gt;event_hub_namespace parameter in the config file, but I've not been successful at figuring out what the problem is.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="s1"&gt;Thank you.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jun 2021 21:45:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-cloud-services/m-p/557084#M92182</guid>
      <dc:creator>gazoscreek</dc:creator>
      <dc:date>2021-06-24T21:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft cloud services</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-cloud-services/m-p/559953#M92580</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;gazoscreek,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sorry for the late response. I am still having the same issue.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I am waiting for someone from this community to shed some light.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jul 2021 02:14:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-cloud-services/m-p/559953#M92580</guid>
      <dc:creator>KnightRider</dc:creator>
      <dc:date>2021-07-19T02:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft cloud services</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-cloud-services/m-p/561892#M100085</link>
      <description>&lt;P&gt;I am having the same issue.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 14:21:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-cloud-services/m-p/561892#M100085</guid>
      <dc:creator>n0psl1de</dc:creator>
      <dc:date>2021-08-03T14:21:58Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft cloud services</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-cloud-services/m-p/565532#M100618</link>
      <description>&lt;P class="lia-align-left"&gt;&lt;FONT face="book antiqua,palatino"&gt;Wondering if someone have resolved this issue already as I am having same issue.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2021 17:41:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-cloud-services/m-p/565532#M100618</guid>
      <dc:creator>cdahal</dc:creator>
      <dc:date>2021-09-01T17:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft cloud services</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-cloud-services/m-p/576485#M101864</link>
      <description>&lt;P&gt;Hey all, I am experiencing the same issue.&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/236176"&gt;@KnightRider&lt;/a&gt;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/226003"&gt;@gazoscreek&lt;/a&gt;&amp;nbsp;any update or working usecase?&lt;/P&gt;</description>
      <pubDate>Sat, 27 Nov 2021 17:47:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-cloud-services/m-p/576485#M101864</guid>
      <dc:creator>maplebuddy</dc:creator>
      <dc:date>2021-11-27T17:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Add-on for Microsoft cloud services</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-cloud-services/m-p/576491#M101866</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/232202"&gt;@Knightrider1234&lt;/a&gt;&amp;nbsp; I found a solution. I searched and couldn't find an answer so I will post this here for anyone else that is experiencing the issue above.&lt;BR /&gt;&lt;SPAN&gt;I initially&amp;nbsp;started with the Microsoft Azure Add-on for Splunk. I found "The Event Hub input has been deprecated in this add-on. Please use the Splunk supported Splunk Add-on for Microsoft Cloud Services&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;to ingest Event Hub data" on the inputs page of the app.&lt;BR /&gt;&lt;BR /&gt;I then figured out the difference:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Microsoft Azure Add on for Splunk (now deprecated)&lt;BR /&gt;-&amp;gt; ingests Eventhubs through old ClientSecret String&lt;/P&gt;&lt;P&gt;Splunk Add-on for Microsoft Cloud Services&lt;BR /&gt;-&amp;gt; ingests Eventhubs through modern Azure-AD app with Reader rights into eventhub&lt;/P&gt;&lt;P&gt;You must navigate to Subscriptions -&amp;gt; your subscription -&amp;gt; Access Control (IAM) -&amp;gt; Select (+Add) and give the Splunk app Azure Event Hubs Data Receiver. In the Event Hub set-up of the Splunk Add-on for Microsoft Cloud Services give the FQDN only (e.g.&amp;nbsp;lab-eventhub.servicebus.windows.net) and provide the event-hub name in the following field. This worked for me and I immediately started getting logs in.&lt;BR /&gt;&lt;BR /&gt;Hope this helps!&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Nov 2021 20:46:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Add-on-for-Microsoft-cloud-services/m-p/576491#M101866</guid>
      <dc:creator>maplebuddy</dc:creator>
      <dc:date>2021-11-27T20:46:30Z</dc:date>
    </item>
  </channel>
</rss>

