<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue setting up Microsoft OMS Modular Inputs TA in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333261#M93446</link>
    <description>&lt;P&gt;Looks like I'm still receiving the following error:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;03-07-2018 19:32:48.346 +0000 ERROR ExecProcessor - message from "python /opt/app/splunk/etc/apps/TA-OMS_Inputs/bin/oms_inputs.py" ERRORGet Token request returned http error: 400 and server response: {"error":"unauthorized_client","error_description":"AADSTS70001: Application with identifier '*' was not found in the directory a74cd446-d03c-4d05-afea-429e248a5fc4\r\nTrace ID: b8f81f70-b64b-42ad-b497-8237e9e71000\r\nCorrelation ID: f3d3d29d-cb52-4a91-8cb8-fbabdfc75cfb\r\nTimestamp: 2018-03-07 19:32:48Z","error_codes":[70001],"timestamp":"2018-03-07 19:32:48Z","trace_id":"b8f81f70-b64b-42ad-b497-8237e9e71000","correlation_id":"f3d3d29d-cb52-4a91-8cb8-fbabdfc75cfb"}
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 07 Mar 2018 19:35:13 GMT</pubDate>
    <dc:creator>travis_lelle</dc:creator>
    <dc:date>2018-03-07T19:35:13Z</dc:date>
    <item>
      <title>Issue setting up Microsoft OMS Modular Inputs TA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333254#M93439</link>
      <description>&lt;P&gt;I'm trying to setup the TA, and have filled out all of the required fields (information taken from an azure subscription), and we aren't pulling data, but are seeing the following error messages occur&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;01-24-2018 14:58:48.386 +0000 ERROR ExecProcessor - message from "python /opt/app/splunk/etc/apps/TA-OMS_Inputs/bin/oms_inputs.py" ERRORacquire_token_with_client_credentials() takes exactly 4 arguments (5 given)

2018-01-24 15:00:00,624 ERROR pid=115140 tid=MainThread file=configuration_check.py:run:164 | status="completed" task="confcheck_script_errors" message="msg="A script exited abnormally" input="/opt/app/splunk/etc/apps/TA-OMS_Inputs/bin/oms_inputs.py" stanza="oms_inputs://oms_splunk" status="exited with code 1""
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any help would be appreciated. @jkat54&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2018 15:09:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333254#M93439</guid>
      <dc:creator>travis_lelle</dc:creator>
      <dc:date>2018-01-24T15:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: Issue setting up Microsoft OMS Modular Inputs TA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333255#M93440</link>
      <description>&lt;P&gt;I have the same problem with the "Microsoft OMS Modular Inputs TA" application. &lt;BR /&gt;
Here is the error from the Splunk server log:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;02-20-2018 11:26:20.015 -0500 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-OMS_Inputs/bin/oms_inputs.py" ERRORacquire_token_with_client_credentials() takes exactly 4 arguments (5 given)&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Besides that, I only see the following lines when searching for "TA-OMS_Inputs":&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;02-20-2018 11:25:47.960 -0500 INFO  ExecProcessor - New scheduled exec process: python /opt/splunk/etc/apps/TA-OMS_Inputs/bin/oms_inputs.py&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;I have reviewed "Tennant ID", "Application ID" and "Application Key" used in the Splunk input configuration (in both the UI and inputs.conf), and these values seem to be OK - they do not contain spaces or hidden characters. &lt;/P&gt;

&lt;P&gt;Is there any way to get more verbose log, or to find out what exactly does the application send to Azure/OMS?&lt;/P&gt;

&lt;P&gt;Any help or suggestion would be appreciated. &lt;BR /&gt;
Many thanks, &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199197"&gt;@jkat54&lt;/a&gt; and anyone else willing to help!&lt;/P&gt;

&lt;P&gt;,@jkat54, &lt;/P&gt;

&lt;P&gt;I have the same problem with the "Microsoft OMS Modular Inputs TA" application. Here is the error from the Splunk server log:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;02-20-2018 11:26:20.015 -0500 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-OMS_Inputs/bin/oms_inputs.py" ERRORacquire_token_with_client_credentials() takes exactly 4 arguments (5 given)&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;I have reviewed "Tennant ID", "Application ID" and "Application Key" used in the Splunk input configuration (in both the UI and inputs.conf), and these values seem to be OK - they do not contain spaces or hidden characters. &lt;/P&gt;

&lt;P&gt;Is there any way to get more verbose log, or to find out what exactly does the application send to Azure/OMS?&lt;/P&gt;

&lt;P&gt;Any help would be appreciated. Many thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:06:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333255#M93440</guid>
      <dc:creator>luke75</dc:creator>
      <dc:date>2020-09-29T18:06:15Z</dc:date>
    </item>
    <item>
      <title>Re: Issue setting up Microsoft OMS Modular Inputs TA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333256#M93441</link>
      <description>&lt;P&gt;I may have found a bug.&lt;/P&gt;

&lt;P&gt;Can you try editing bin/oms_inputs.py lines 140 and 141?&lt;/P&gt;

&lt;P&gt;Change: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;        inputname = input_name.replace("://","_")
        token_response = context.acquire_token_with_client_credentials('https://management.core.windows.net/', application_id, inputname, application_key)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;To:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;        token_response = context.acquire_token_with_client_credentials('https://management.core.windows.net/', application_id, application_key)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Then save the oms_inputs.py and see if the error goes away.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2018 21:43:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333256#M93441</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-02-28T21:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: Issue setting up Microsoft OMS Modular Inputs TA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333257#M93442</link>
      <description>&lt;P&gt;It looks like we're getting closer. The new error I'm getting is:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;03-02-2018 15:41:20.649 +0000 ERROR ExecProcessor - message from "python /opt/app/splunk/etc/apps/TA-OMS_Inputs/bin/oms_inputs.py" ERRORGet Token request returned http error: 400 and server response: {"error":"unauthorized_client","error_description":"AADSTS70001: Application with identifier '*' was not found in the directory a74cd446-d03c-4d05-afea-429e248a5fc4\r\nTrace ID: e68d1ee2-afbd-4e6c-b520-8fa55f020a00\r\nCorrelation ID: 84105cb3-2af7-4d39-9833-5090338c8a08\r\nTimestamp: 2018-03-02 15:41:20Z","error_codes":[70001],"timestamp":"2018-03-02 15:41:20Z","trace_id":"e68d1ee2-afbd-4e6c-b520-8fa55f020a00","correlation_id":"84105cb3-2af7-4d39-9833-5090338c8a08"}
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I think the reason may be because of asterisks in the Resource Group, Application ID, and Application Key. Can you provide some guidance on what might typically go into these fields. Pardon my lack of knowledge with OMS, I'm just trying to get the data into Splunk for another party.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 15:46:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333257#M93442</guid>
      <dc:creator>travis_lelle</dc:creator>
      <dc:date>2018-03-02T15:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issue setting up Microsoft OMS Modular Inputs TA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333258#M93443</link>
      <description>&lt;P&gt;It looks like I made some error while modifying the input file, because I see the following in the Splunk log now:&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;03-01-2018 08:28:51.341 -0500 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-OMS_Inputs/bin/oms_inputs.py" ERRORlocal variable 'data' referenced before assignment&lt;BR /&gt;
host =  qa-splutil-lx01 source =    /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd&lt;BR /&gt;
03-01-2018 08:28:19.588 -0500 INFO  ExecProcessor - New scheduled exec process: python /opt/splunk/etc/apps/TA-OMS_Inputs/bin/oms_inputs.py&lt;BR /&gt;
host =  qa-splutil-lx01 source =    /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;@jkat54, could you please share the complete input file? Thank you very much for any help or advice!&lt;/P&gt;</description>
      <pubDate>Fri, 02 Mar 2018 16:14:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333258#M93443</guid>
      <dc:creator>luke75</dc:creator>
      <dc:date>2018-03-02T16:14:35Z</dc:date>
    </item>
    <item>
      <title>Re: Issue setting up Microsoft OMS Modular Inputs TA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333259#M93444</link>
      <description>&lt;P&gt;It looks like I made some error while modifying the input file, because I see the following in the Splunk log now:&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;03-01-2018 08:28:51.341 -0500 ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-OMS_Inputs/bin/oms_inputs.py" ERRORlocal variable 'data' referenced before assignment host = qa-splutil-lx01 source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd&lt;/STRONG&gt; &lt;BR /&gt;
03-01-2018 08:28:19.588 -0500 INFO ExecProcessor - New scheduled exec process: python /opt/splunk/etc/apps/TA-OMS_Inputs/bin/oms_inputs.py host = qa-splutil-lx01 source = /opt/splunk/var/log/splunk/splunkd.log sourcetype = splunkd&lt;/P&gt;

&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/199197"&gt;@jkat54&lt;/a&gt;, could you please share the complete input file? Thank you very much for any help or advice!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:24:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333259#M93444</guid>
      <dc:creator>luke75</dc:creator>
      <dc:date>2020-09-29T18:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: Issue setting up Microsoft OMS Modular Inputs TA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333260#M93445</link>
      <description>&lt;P&gt;Can you please upgrade to the latest version of the app (v1.2) and let me know if the problem is resolved?&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/3764"&gt;https://splunkbase.splunk.com/app/3764&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
JKat&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 19:22:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333260#M93445</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-03-07T19:22:57Z</dc:date>
    </item>
    <item>
      <title>Re: Issue setting up Microsoft OMS Modular Inputs TA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333261#M93446</link>
      <description>&lt;P&gt;Looks like I'm still receiving the following error:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;03-07-2018 19:32:48.346 +0000 ERROR ExecProcessor - message from "python /opt/app/splunk/etc/apps/TA-OMS_Inputs/bin/oms_inputs.py" ERRORGet Token request returned http error: 400 and server response: {"error":"unauthorized_client","error_description":"AADSTS70001: Application with identifier '*' was not found in the directory a74cd446-d03c-4d05-afea-429e248a5fc4\r\nTrace ID: b8f81f70-b64b-42ad-b497-8237e9e71000\r\nCorrelation ID: f3d3d29d-cb52-4a91-8cb8-fbabdfc75cfb\r\nTimestamp: 2018-03-07 19:32:48Z","error_codes":[70001],"timestamp":"2018-03-07 19:32:48Z","trace_id":"b8f81f70-b64b-42ad-b497-8237e9e71000","correlation_id":"f3d3d29d-cb52-4a91-8cb8-fbabdfc75cfb"}
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 07 Mar 2018 19:35:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333261#M93446</guid>
      <dc:creator>travis_lelle</dc:creator>
      <dc:date>2018-03-07T19:35:13Z</dc:date>
    </item>
    <item>
      <title>Re: Issue setting up Microsoft OMS Modular Inputs TA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333262#M93447</link>
      <description>&lt;P&gt;Hello Travis.&lt;/P&gt;

&lt;P&gt;I am not 100% sure whether this is your problem, but from the error message provided it looks like you have used "*" as "Application ID" in the Splunk Input properties. This will not work for sure. Application ID and Application Key are used to authorize Splunk in Azure. You have to obtain their values in the properties of the Splunk application you have registered in Azure. Please find the step-by-step guide for registering Splunk in Azure and setting up inputs here: &lt;A href="https://www.splunk.com/blog/2017/07/27/splunking-microsoft-cloud-data-part-1.html"&gt;https://www.splunk.com/blog/2017/07/27/splunking-microsoft-cloud-data-part-1.html&lt;/A&gt; .  &lt;/P&gt;

&lt;P&gt;Regards&lt;BR /&gt;
Lukas&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 10:14:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333262#M93447</guid>
      <dc:creator>luke75</dc:creator>
      <dc:date>2018-03-08T10:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: Issue setting up Microsoft OMS Modular Inputs TA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333263#M93448</link>
      <description>&lt;P&gt;I agree with Lukas.  This error message is saying you used * as your application Id.  It should be something different,&lt;/P&gt;</description>
      <pubDate>Thu, 08 Mar 2018 12:02:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333263#M93448</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-03-08T12:02:24Z</dc:date>
    </item>
    <item>
      <title>Re: Issue setting up Microsoft OMS Modular Inputs TA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333264#M93449</link>
      <description>&lt;P&gt;Please run this search and let me know the results:&lt;/P&gt;

&lt;P&gt;index=_internal sourcetype=splunk_python OR (sourcetype=splunkd AND oms_inputs.py)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:25:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333264#M93449</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2020-09-29T18:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: Issue setting up Microsoft OMS Modular Inputs TA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333265#M93450</link>
      <description>&lt;P&gt;@travis, Please run this search and let me know the results:&lt;/P&gt;

&lt;P&gt;index=_internal sourcetype=splunk_python OR (sourcetype=splunkd AND oms_inputs.py)&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:31:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333265#M93450</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2020-09-29T18:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: Issue setting up Microsoft OMS Modular Inputs TA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333266#M93451</link>
      <description>&lt;P&gt;This app has been deprecated and a new log analytics app has replaced it.  Please give the new app a try:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/4127/"&gt;https://splunkbase.splunk.com/app/4127/&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;All previously known bugs have been addressed.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Aug 2018 14:32:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333266#M93451</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-08-25T14:32:28Z</dc:date>
    </item>
    <item>
      <title>Re: Issue setting up Microsoft OMS Modular Inputs TA</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333267#M93452</link>
      <description>&lt;P&gt;@luke75 Did the upgrade solve your problem?&lt;/P&gt;</description>
      <pubDate>Wed, 14 Nov 2018 11:10:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-setting-up-Microsoft-OMS-Modular-Inputs-TA/m-p/333267#M93452</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2018-11-14T11:10:21Z</dc:date>
    </item>
  </channel>
</rss>

