<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to resolve the Fail to update configuration for add-on error on heavy Forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-the-Fail-to-update-configuration-for-add-on-error/m-p/306132#M57757</link>
    <description>&lt;P&gt;Yes I tried installing the add-on directly on HF, it shows the above errors and then I tried the copy option.&lt;/P&gt;</description>
    <pubDate>Thu, 30 Mar 2017 15:23:09 GMT</pubDate>
    <dc:creator>kiran331</dc:creator>
    <dc:date>2017-03-30T15:23:09Z</dc:date>
    <item>
      <title>How to resolve the Fail to update configuration for add-on error on heavy Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-the-Fail-to-update-configuration-for-add-on-error/m-p/306128#M57753</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;I Installed a Add-on on the Heavy Forwarder, when I try to setup the Add-On using API and credentials, its showing the error&lt;/P&gt;

&lt;P&gt;"Fail to update configuration for add-on xxx" but the add-on is working on other heavy Forwarder -2. Both are running under splunk user. I tried to copy the installation file from one HF to other and i got the below error, if its a permissions issue how to resolve this one?&lt;/P&gt;

&lt;P&gt;"Fail to load configuration for add-on xxx"&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 14:48:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-the-Fail-to-update-configuration-for-add-on-error/m-p/306128#M57753</guid>
      <dc:creator>kiran331</dc:creator>
      <dc:date>2017-03-30T14:48:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve the Fail to update configuration for add-on error on heavy Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-the-Fail-to-update-configuration-for-add-on-error/m-p/306129#M57754</link>
      <description>&lt;P&gt;Why are you trying to configure the add-on on two different heavy forwarders? Are you planning to manually split input collection between two heavy forwarders without overlapping them?&lt;/P&gt;

&lt;P&gt;Which add-on is this?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 15:06:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-the-Fail-to-update-configuration-for-add-on-error/m-p/306129#M57754</guid>
      <dc:creator>rpille_splunk</dc:creator>
      <dc:date>2017-03-30T15:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve the Fail to update configuration for add-on error on heavy Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-the-Fail-to-update-configuration-for-add-on-error/m-p/306130#M57755</link>
      <description>&lt;P&gt;I need this on only one Heavy Forwarder, For Testing I installed it on other. Its working on other Heavy Forwarder. Its TA-CiscoAmp&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 15:12:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-the-Fail-to-update-configuration-for-add-on-error/m-p/306130#M57755</guid>
      <dc:creator>kiran331</dc:creator>
      <dc:date>2017-03-30T15:12:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve the Fail to update configuration for add-on error on heavy Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-the-Fail-to-update-configuration-for-add-on-error/m-p/306131#M57756</link>
      <description>&lt;P&gt;Try configuring it without copying over the configurations from the first forwarder. Because this add-on involves credentials, copying over the files probably will not work. &lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 15:17:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-the-Fail-to-update-configuration-for-add-on-error/m-p/306131#M57756</guid>
      <dc:creator>rpille_splunk</dc:creator>
      <dc:date>2017-03-30T15:17:17Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve the Fail to update configuration for add-on error on heavy Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-the-Fail-to-update-configuration-for-add-on-error/m-p/306132#M57757</link>
      <description>&lt;P&gt;Yes I tried installing the add-on directly on HF, it shows the above errors and then I tried the copy option.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 15:23:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-the-Fail-to-update-configuration-for-add-on-error/m-p/306132#M57757</guid>
      <dc:creator>kiran331</dc:creator>
      <dc:date>2017-03-30T15:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve the Fail to update configuration for add-on error on heavy Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-the-Fail-to-update-configuration-for-add-on-error/m-p/306133#M57758</link>
      <description>&lt;P&gt;I'm not familiar with that add-on, so this advice is generic. If you've tried manually configuring it on the new forwarder, then I'd suggest disabling the add-on on the first forwarder and trying again. &lt;/P&gt;

&lt;P&gt;If that doesn't work, look for all of the ways in which the new forwarder is different from the one on which you installed the add-on for testing, or anything that might be different about the configuration on the new forwarder vs the old one. Perhaps your API key expired? Perhaps you've exceeded your rate limit with the number of API calls you already made? Perhaps your browser is caching different credentials when you configure your connection to the API? &lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 16:50:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-the-Fail-to-update-configuration-for-add-on-error/m-p/306133#M57758</guid>
      <dc:creator>rpille_splunk</dc:creator>
      <dc:date>2017-03-30T16:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: How to resolve the Fail to update configuration for add-on error on heavy Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-the-Fail-to-update-configuration-for-add-on-error/m-p/306134#M57759</link>
      <description>&lt;P&gt;Hi rpille,&lt;/P&gt;

&lt;P&gt;I see the below error i n python.log ,when i setup the add-on. &lt;/P&gt;

&lt;P&gt;2017-03-30 13:11:46,364 ERROR Run function: delete_password failed: Traceback (most recent call last):&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/solnlib/utils.py", line 150, in wrapper&lt;BR /&gt;
    return func(*args, **kwargs)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/solnlib/credentials.py", line 179, in delete_password&lt;BR /&gt;
    all_passwords = self._storage_passwords.list()&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/splunklib/client.py", line 1459, in list&lt;BR /&gt;
    return list(self.iter(count=count, **kwargs))&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/splunklib/client.py", line 1419, in iter&lt;BR /&gt;
    items = self._load_list(response)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/splunklib/client.py", line 1325, in _load_list&lt;BR /&gt;
    entries = _load_atom_entries(response)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/splunklib/client.py", line 201, in _load_atom_entries&lt;BR /&gt;
    r = _load_atom(response)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/splunklib/client.py", line 196, in _load_atom&lt;BR /&gt;
    return data.load(response.body.read(), match)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/splunklib/data.py", line 77, in load&lt;BR /&gt;
    root = XML(text)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/xml/etree/ElementTree.py", line 1300, in XML&lt;BR /&gt;
    parser.feed(text)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/xml/etree/ElementTree.py", line 1642, in feed&lt;BR /&gt;
    self._raiseerror(v)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/xml/etree/ElementTree.py", line 1506, in _raiseerror&lt;BR /&gt;
    raise err&lt;BR /&gt;
ParseError: not well-formed (invalid token): line 33, column 37&lt;BR /&gt;
.&lt;BR /&gt;
2017-03-30 13:11:46,365 ERROR Run function: set_password failed: Traceback (most recent call last):&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/solnlib/utils.py", line 150, in wrapper&lt;BR /&gt;
    return func(*args, **kwargs)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/solnlib/credentials.py", line 138, in set_password&lt;BR /&gt;
    self.delete_password(user)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/solnlib/utils.py", line 150, in wrapper&lt;BR /&gt;
    return func(*args, **kwargs)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/solnlib/credentials.py", line 179, in delete_password&lt;BR /&gt;
    all_passwords = self._storage_passwords.list()&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/splunklib/client.py", line 1459, in list&lt;BR /&gt;
    return list(self.iter(count=count, **kwargs))&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/splunklib/client.py", line 1419, in iter&lt;BR /&gt;
    items = self._load_list(response)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/splunklib/client.py", line 1325, in _load_list&lt;BR /&gt;
    entries = _load_atom_entries(response)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/splunklib/client.py", line 201, in _load_atom_entries&lt;BR /&gt;
    r = _load_atom(response)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/splunklib/client.py", line 196, in _load_atom&lt;BR /&gt;
    return data.load(response.body.read(), match)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/splunklib/data.py", line 77, in load&lt;BR /&gt;
    root = XML(text)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/xml/etree/ElementTree.py", line 1300, in XML&lt;BR /&gt;
    parser.feed(text)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/xml/etree/ElementTree.py", line 1642, in feed&lt;BR /&gt;
    self._raiseerror(v)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/xml/etree/ElementTree.py", line 1506, in _raiseerror&lt;BR /&gt;
    raise err&lt;BR /&gt;
ParseError: not well-formed (invalid token): line 33, column 37&lt;BR /&gt;
.&lt;BR /&gt;
2017-03-30 13:11:46,366 ERROR Run function: update failed: Traceback (most recent call last):&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/solnlib/utils.py", line 150, in wrapper&lt;BR /&gt;
    return func(*args, **kwargs)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/solnlib/conf_manager.py", line 251, in update&lt;BR /&gt;
    encrypt_keys)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/solnlib/conf_manager.py", line 110, in _encrypt_stanza&lt;BR /&gt;
    self._cred_mgr.set_password(stanza_name, json.dumps(encrypt_fields))&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/solnlib/utils.py", line 150, in wrapper&lt;BR /&gt;
    return func(*args, **kwargs)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/solnlib/credentials.py", line 138, in set_password&lt;BR /&gt;
    self.delete_password(user)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/solnlib/utils.py", line 150, in wrapper&lt;BR /&gt;
    return func(*args, **kwargs)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/solnlib/credentials.py", line 179, in delete_password&lt;BR /&gt;
    all_passwords = self._storage_passwords.list()&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/splunklib/client.py", line 1459, in list&lt;BR /&gt;
    return list(self.iter(count=count, **kwargs))&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/splunklib/client.py", line 1419, in iter&lt;BR /&gt;
    items = self._load_list(response)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/splunklib/client.py", line 1325, in _load_list&lt;BR /&gt;
    entries = _load_atom_entries(response)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/splunklib/client.py", line 201, in _load_atom_entries&lt;BR /&gt;
    r = _load_atom(response)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/splunklib/client.py", line 196, in _load_atom&lt;BR /&gt;
    return data.load(response.body.read(), match)&lt;BR /&gt;
  File "/opt/splunk/etc/apps/TA-ciscoAMP4ep/bin/ta_ciscoamp4ep/splunklib/data.py", line 77, in load&lt;BR /&gt;
    root = XML(text)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/xml/etree/ElementTree.py", line 1300, in XML&lt;BR /&gt;
    parser.feed(text)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/xml/etree/ElementTree.py", line 1642, in feed&lt;BR /&gt;
    self._raiseerror(v)&lt;BR /&gt;
  File "/opt/splunk/lib/python2.7/xml/etree/ElementTree.py", line 1506, in _raiseerror&lt;BR /&gt;
    raise err&lt;BR /&gt;
ParseError: not well-formed (invalid token): line 33, column 37&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:29:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-resolve-the-Fail-to-update-configuration-for-add-on-error/m-p/306134#M57759</guid>
      <dc:creator>kiran331</dc:creator>
      <dc:date>2020-09-29T13:29:45Z</dc:date>
    </item>
  </channel>
</rss>

