All Apps and Add-ons

Error 503 while collecting data

nessupport
Explorer

Hi,

We are trying to collect email informations in our Splunk platform. We use an office365 admin account but our index is not fed.
This app looks simple to configure. By reading the documentation we saw that this add-on just join the office365 API REST with this link : https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace that looks available.

We got this error in /opt/splunk/var/log/splunk/ta_ms_o365_reporting_ms_o365_message_trace.log

2018-03-09 14:08:10,283 WARNING pid=7027 tid=MainThread file=utils.py:wrapper:157 | Run function: get failed: Traceback (most recent call last):
File "/opt/splunk/etc/apps/TA-MS_O365_Reporting/bin/ta_ms_o365_reporting/solnlib/utils.py", line 154, in wrapper
return func(*args, **kwargs)
File "/opt/splunk/etc/apps/TA-MS_O365_Reporting/bin/ta_ms_o365_reporting/solnlib/modular_input/checkpointer.py", line 219, in get
record = self._collection_data.query_by_id(key)
File "/opt/splunk/etc/apps/TA-MS_O365_Reporting/bin/ta_ms_o365_reporting/solnlib/packages/splunklib/client.py", line 3637, in query_by_id
return json.loads(self._get(UrlEncoded(str(id))).body.read())
File "/opt/splunk/etc/apps/TA-MS_O365_Reporting/bin/ta_ms_o365_reporting/solnlib/packages/splunklib/client.py", line 3607, in _get
return self.service.get(self.path + url, owner=self.owner, app=self.app, sharing=self.sharing, **kwargs)
File "/opt/splunk/etc/apps/TA-MS_O365_Reporting/bin/ta_ms_o365_reporting/solnlib/packages/splunklib/binding.py", line 287, in wrapper
return request_fun(self, *args, **kwargs)
File "/opt/splunk/etc/apps/TA-MS_O365_Reporting/bin/ta_ms_o365_reporting/solnlib/packages/splunklib/binding.py", line 69, in new_f
val = f(*args, **kwargs)
File "/opt/splunk/etc/apps/TA-MS_O365_Reporting/bin/ta_ms_o365_reporting/solnlib/packages/splunklib/binding.py", line 665, in get
response = self.http.get(path, self._auth_headers, **query)
File "/opt/splunk/etc/apps/TA-MS_O365_Reporting/bin/ta_ms_o365_reporting/solnlib/packages/splunklib/binding.py", line 1160, in get
return self.request(url, { 'method': "GET", 'headers': headers })
File "/opt/splunk/etc/apps/TA-MS_O365_Reporting/bin/ta_ms_o365_reporting/solnlib/packages/splunklib/binding.py", line 1221, in request
raise HTTPError(response)
HTTPError: HTTP 503 Service Unavailable -- KV Store initialization failed. Please contact your system administrator.
.
2018-03-09 14:08:10,284 ERROR pid=7027 tid=MainThread file=base_modinput.py:log_error:307 | Get error when collecting events.
Traceback (most recent call last):
File "/opt/splunk/etc/apps/TA-MS_O365_Reporting/bin/ta_ms_o365_reporting/modinput_wrapper/base_modinput.py", line 127, in stream_events
self.collect_events(ew)
File "/opt/splunk/etc/apps/TA-MS_O365_Reporting/bin/ms_o365_message_trace.py", line 72, in collect_events
input_module.collect_events(self, ew)
File "/opt/splunk/etc/apps/TA-MS_O365_Reporting/bin/input_module_ms_o365_message_trace.py", line 48, in collect_events
start_date = get_start_date(helper, check_point_key)
File "/opt/splunk/etc/apps/TA-MS_O365_Reporting/bin/input_module_ms_o365_message_trace.py", line 22, in get_start_date
d = helper.get_check_point(check_point_key)
File "/opt/splunk/etc/apps/TA-MS_O365_Reporting/bin/ta_ms_o365_reporting/modinput_wrapper/base_modinput.py", line 519, in get_check_point
return self.ckpt.get(key)
File "/opt/splunk/etc/apps/TA-MS_O365_Reporting/bin/ta_ms_o365_reporting/solnlib/utils.py", line 167, in wrapper
raise last_ex
HTTPError: HTTP 503 Service Unavailable -- KV Store initialization failed. Please contact your system administrator.

Does anyone have an idea about this issue?

0 Karma
1 Solution

nessupport
Explorer

We saw that our KVstore service wasn't configured properly. We fixed it and that resolved the problem.

View solution in original post

0 Karma

nessupport
Explorer

We saw that our KVstore service wasn't configured properly. We fixed it and that resolved the problem.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

@nessupport If your problem is resolved, please accept the answer to help future readers.

---
If this reply helps you, Karma would be appreciated.
0 Karma

p_gurav
Champion

Can you also check _internal logs?

0 Karma

nessupport
Explorer

Hi, _internal give almost the same informations.

Anyway, we saw that our KVstore service wasn't configured properly. We fixed it and that resolved the problem.

0 Karma
Get Updates on the Splunk Community!

What's new in Splunk Cloud Platform 9.1.2312?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2312! Analysts can ...

What’s New in Splunk Security Essentials 3.8.0?

Splunk Security Essentials (SSE) is an app that can amplify the power of your existing Splunk Cloud Platform, ...

Let’s Get You Certified – Vegas-Style at .conf24

Are you ready to level up your Splunk game? Then, let’s get you certified live at .conf24 – our annual user ...