I am trying to configure the trial of Splunk Business Flow on Splunk Enterprise (a trial) on Windows.
I checked to have respected all requirements following the documentation, and all deployment check results in the app are ok.
Otherwise, when I try to complete the registration, I receive this error:
Error processing registration: register error during encryption/decryption. X-Request-ID: e3f95c26-1112-442a-bec1-7032e4b1b85f.
In the log error, I find this:
** [SplunkClient] ERROR requestID:8c79e81a-473e-4b83-a480-09b4a5be9bd3 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem**
Indeed there is not that pem file in that directory.
I tried from installing Business Flow app from the App section in Splunk and from file both.
If someone could help me, I would be really thankful!
We have identified the issue as being related to Windows 10. We are working on a fix and I will let you know when it's fixed.
Hi!
I cannot upload a file here because I do not have karma points enough. I copy here part of the log, from the beginning.
Thank you
*2020-02-25 10:34:14,274 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 10:34:14,345 [SplunkClient] INFO requestID:4349b403-4c94-4bc5-9600-c39a62d93235 PEM password not found, generating new password.
2020-02-25 10:34:14,777 [SplunkClient] INFO requestID:4349b403-4c94-4bc5-9600-c39a62d93235 Storing new PEM password.
2020-02-25 10:34:14,797 [SplunkClient] INFO requestID:4349b403-4c94-4bc5-9600-c39a62d93235 Successfully stored new PEM password.
2020-02-25 10:34:14,798 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 10:34:14,818 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 10:34:15,649 [SplunkClient] INFO requestID:4349b403-4c94-4bc5-9600-c39a62d93235 PEM file not found in KV store, read PEM file locally
2020-02-25 10:34:15,656 [SplunkClient] INFO requestID:4349b403-4c94-4bc5-9600-c39a62d93235 Store PEM file in KV store
2020-02-25 10:34:15,703 [SplunkClient] INFO requestID:4349b403-4c94-4bc5-9600-c39a62d93235 PEM file not found in KV store, read PEM file locally
2020-02-25 10:34:15,710 [SplunkClient] INFO requestID:4349b403-4c94-4bc5-9600-c39a62d93235 Store PEM file in KV store
2020-02-25 10:34:15,735 [SplunkClient] INFO requestID:4349b403-4c94-4bc5-9600-c39a62d93235 PEM file not found in KV store, read PEM file locally
2020-02-25 10:34:15,742 [SplunkClient] ERROR requestID:4349b403-4c94-4bc5-9600-c39a62d93235 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 10:34:15,742 [SBFRestManager] INFO requestID:4349b403-4c94-4bc5-9600-c39a62d93235 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 10:34:15,742 [SBFRestManager] INFO requestID:4349b403-4c94-4bc5-9600-c39a62d93235 Requesting "/init" endpoint
2020-02-25 10:34:15,993 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 10:34:16,055 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 10:34:16,079 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 10:34:16,143 [SplunkClient] INFO requestID:8c79e81a-473e-4b83-a480-09b4a5be9bd3 PEM file not found in KV store, read PEM file locally
2020-02-25 10:34:16,148 [SplunkClient] ERROR requestID:8c79e81a-473e-4b83-a480-09b4a5be9bd3 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 10:34:16,148 [SBFRestManager] INFO requestID:8c79e81a-473e-4b83-a480-09b4a5be9bd3 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 10:34:16,148 [SBFRestManager] INFO requestID:8c79e81a-473e-4b83-a480-09b4a5be9bd3 Requesting "/register_payload" endpoint
2020-02-25 10:34:18,818 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 10:34:18,865 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 10:34:18,888 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 10:34:18,949 [SplunkClient] INFO requestID:65b7d256-3b42-4e58-aec2-971c3621e0cc PEM file not found in KV store, read PEM file locally
2020-02-25 10:34:18,965 [SplunkClient] ERROR requestID:65b7d256-3b42-4e58-aec2-971c3621e0cc Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 10:34:18,965 [SBFRestManager] INFO requestID:65b7d256-3b42-4e58-aec2-971c3621e0cc Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 10:34:18,965 [SBFRestManager] INFO requestID:65b7d256-3b42-4e58-aec2-971c3621e0cc Requesting "/deployment_check" endpoint
2020-02-25 10:34:18,966 [DeploymentCheck] INFO requestID:65b7d256-3b42-4e58-aec2-971c3621e0cc Starting deployment check
2020-02-25 10:34:23,032 [DeploymentCheck] INFO requestID:65b7d256-3b42-4e58-aec2-971c3621e0cc {
"nodeName": "T470-PF0Y56UA",
"results": [
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://us.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 09:34:17 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://us.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://eu.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 09:34:18 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://eu.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://apac.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 09:34:20 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://apac.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {},
"isError": false,
"testName": "Testing app install folder permissions"
}
]
}
2020-02-25 14:02:48,443 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 14:02:48,524 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 14:02:48,551 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 14:02:48,604 [SplunkClient] INFO requestID:cfbe699f-388b-4b61-bd11-345be6f899d2 PEM file not found in KV store, read PEM file locally
2020-02-25 14:02:48,611 [SplunkClient] ERROR requestID:cfbe699f-388b-4b61-bd11-345be6f899d2 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 14:02:48,611 [SBFRestManager] INFO requestID:cfbe699f-388b-4b61-bd11-345be6f899d2 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 14:02:48,611 [SBFRestManager] INFO requestID:cfbe699f-388b-4b61-bd11-345be6f899d2 Requesting "/init" endpoint
2020-02-25 14:02:49,219 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 14:02:49,296 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 14:02:49,315 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 14:02:49,350 [SplunkClient] INFO requestID:b0355b8c-c958-40d1-a8d3-4aafde530940 PEM file not found in KV store, read PEM file locally
2020-02-25 14:02:49,355 [SplunkClient] ERROR requestID:b0355b8c-c958-40d1-a8d3-4aafde530940 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 14:02:49,356 [SBFRestManager] INFO requestID:b0355b8c-c958-40d1-a8d3-4aafde530940 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 14:02:49,356 [SBFRestManager] INFO requestID:b0355b8c-c958-40d1-a8d3-4aafde530940 Requesting "/register_payload" endpoint
2020-02-25 14:02:52,029 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 14:02:52,069 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 14:02:52,082 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 14:02:52,117 [SplunkClient] INFO requestID:73926389-4a50-485c-b850-1b0db86425b0 PEM file not found in KV store, read PEM file locally
2020-02-25 14:02:52,122 [SplunkClient] ERROR requestID:73926389-4a50-485c-b850-1b0db86425b0 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 14:02:52,122 [SBFRestManager] INFO requestID:73926389-4a50-485c-b850-1b0db86425b0 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 14:02:52,122 [SBFRestManager] INFO requestID:73926389-4a50-485c-b850-1b0db86425b0 Requesting "/deployment_check" endpoint
2020-02-25 14:02:52,123 [DeploymentCheck] INFO requestID:73926389-4a50-485c-b850-1b0db86425b0 Starting deployment check
2020-02-25 14:02:55,867 [DeploymentCheck] INFO requestID:73926389-4a50-485c-b850-1b0db86425b0 {
"nodeName": "T470-PF0Y56UA",
"results": [
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://us.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 13:02:51 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://us.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://eu.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 13:02:51 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://eu.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://apac.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 13:02:53 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://apac.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {},
"isError": false,
"testName": "Testing app install folder permissions"
}
]
}
2020-02-25 15:28:08,053 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 15:28:08,154 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 15:28:08,171 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 15:28:08,260 [SplunkClient] INFO requestID:5b952c5b-bb6c-41b8-9242-d0e65dcfd05b PEM file not found in KV store, read PEM file locally
2020-02-25 15:28:08,272 [SplunkClient] ERROR requestID:5b952c5b-bb6c-41b8-9242-d0e65dcfd05b Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 15:28:08,272 [SBFRestManager] INFO requestID:5b952c5b-bb6c-41b8-9242-d0e65dcfd05b Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 15:28:08,273 [SBFRestManager] INFO requestID:5b952c5b-bb6c-41b8-9242-d0e65dcfd05b Requesting "/init" endpoint
2020-02-25 15:28:08,637 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 15:28:08,723 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 15:28:08,746 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 15:28:08,797 [SplunkClient] INFO requestID:f2f5070d-d764-4b03-b097-3a1afdf135b6 PEM file not found in KV store, read PEM file locally
2020-02-25 15:28:08,802 [SplunkClient] ERROR requestID:f2f5070d-d764-4b03-b097-3a1afdf135b6 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 15:28:08,802 [SBFRestManager] INFO requestID:f2f5070d-d764-4b03-b097-3a1afdf135b6 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 15:28:08,802 [SBFRestManager] INFO requestID:f2f5070d-d764-4b03-b097-3a1afdf135b6 Requesting "/register_payload" endpoint
2020-02-25 15:28:12,550 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 15:28:12,626 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 15:28:12,648 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 15:28:12,742 [SplunkClient] INFO requestID:c3cd32c5-9aea-46b2-97ea-d394ff3ca1d5 PEM file not found in KV store, read PEM file locally
2020-02-25 15:28:12,764 [SplunkClient] ERROR requestID:c3cd32c5-9aea-46b2-97ea-d394ff3ca1d5 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 15:28:12,764 [SBFRestManager] INFO requestID:c3cd32c5-9aea-46b2-97ea-d394ff3ca1d5 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 15:28:12,764 [SBFRestManager] INFO requestID:c3cd32c5-9aea-46b2-97ea-d394ff3ca1d5 Requesting "/deployment_check" endpoint
2020-02-25 15:28:12,766 [DeploymentCheck] INFO requestID:c3cd32c5-9aea-46b2-97ea-d394ff3ca1d5 Starting deployment check
2020-02-25 15:28:16,265 [DeploymentCheck] INFO requestID:c3cd32c5-9aea-46b2-97ea-d394ff3ca1d5 {
"nodeName": "T470-PF0Y56UA",
"results": [
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://us.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 14:28:11 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://us.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://eu.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 14:28:12 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://eu.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://apac.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 14:28:14 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://apac.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {},
"isError": false,
"testName": "Testing app install folder permissions"
}
]
}
2020-02-25 15:29:45,773 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 15:29:45,903 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 15:29:45,927 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 15:29:45,978 [SplunkClient] INFO requestID:ec0b1c14-df21-4606-8efb-bb9014a78b1e PEM file not found in KV store, read PEM file locally
2020-02-25 15:29:45,985 [SplunkClient] ERROR requestID:ec0b1c14-df21-4606-8efb-bb9014a78b1e Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 15:29:45,986 [SBFRestManager] INFO requestID:ec0b1c14-df21-4606-8efb-bb9014a78b1e Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 15:29:45,986 [SBFRestManager] INFO requestID:ec0b1c14-df21-4606-8efb-bb9014a78b1e Requesting "/init" endpoint
2020-02-25 15:29:46,372 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 15:29:46,425 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 15:29:46,439 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 15:29:46,543 [SplunkClient] INFO requestID:605a4e97-579c-49ed-8755-b8738383b8cb PEM file not found in KV store, read PEM file locally
2020-02-25 15:29:46,554 [SplunkClient] ERROR requestID:605a4e97-579c-49ed-8755-b8738383b8cb Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 15:29:46,554 [SBFRestManager] INFO requestID:605a4e97-579c-49ed-8755-b8738383b8cb Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 15:29:46,556 [SBFRestManager] INFO requestID:605a4e97-579c-49ed-8755-b8738383b8cb Requesting "/register_payload" endpoint
2020-02-25 15:29:49,604 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 15:29:49,690 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 15:29:49,729 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 15:29:49,808 [SplunkClient] INFO requestID:2b8c5525-586b-417a-bb47-478249fc18db PEM file not found in KV store, read PEM file locally
2020-02-25 15:29:49,816 [SplunkClient] ERROR requestID:2b8c5525-586b-417a-bb47-478249fc18db Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 15:29:49,816 [SBFRestManager] INFO requestID:2b8c5525-586b-417a-bb47-478249fc18db Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 15:29:49,816 [SBFRestManager] INFO requestID:2b8c5525-586b-417a-bb47-478249fc18db Requesting "/deployment_check" endpoint
2020-02-25 15:29:49,818 [DeploymentCheck] INFO requestID:2b8c5525-586b-417a-bb47-478249fc18db Starting deployment check
2020-02-25 15:29:54,284 [DeploymentCheck] INFO requestID:2b8c5525-586b-417a-bb47-478249fc18db {
"nodeName": "T470-PF0Y56UA",
"results": [
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://us.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 14:29:48 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://us.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://eu.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 14:29:49 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://eu.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://apac.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 14:29:52 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://apac.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {},
"isError": false,
"testName": "Testing app install folder permissions"
}
]
}
2020-02-25 15:30:13,718 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 15:30:13,827 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 15:30:13,851 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 15:30:13,924 [SplunkClient] INFO requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e PEM file not found in KV store, read PEM file locally
2020-02-25 15:30:13,936 [SplunkClient] ERROR requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 15:30:13,936 [SBFRestManager] INFO requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 15:30:13,936 [SBFRestManager] INFO requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Requesting "/register" endpoint
2020-02-25 15:30:13,964 [RegisterCommand] INFO requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Collecting info needed for registration
2020-02-25 15:30:13,997 [SplunkClient] DEBUG requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Connecting to: https://127.0.0.1:8089/servicesNS/nobody/splunk-business-flow/properties/sbf/server/url_eu
2020-02-25 15:30:14,005 [SplunkClient] DEBUG requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Connecting to: https://127.0.0.1:8089/servicesNS/nobody/splunk-business-flow/properties/sbf/server
2020-02-25 15:30:14,019 [SplunkClient] ERROR requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Failed to execute: https://127.0.0.1:8089/servicesNS/nobody/splunk-business-flow/properties/sbf/server Err: Expecting value: line 1 column 1 (char 0)
Traceback (most recent call last):
File "C:\Program Files\Splunk\etc\apps\splunk-business-flow\bin\splunkd_client.py", line 187, in get_config_url
results[config_name]=json.loads(data)
File "C:\Program Files\Splunk\Python-3.7\lib\json__init.py", line 348, in loads
return default_decoder.decode(s)
File "C:\Program Files\Splunk\Python-3.7\lib\json\decoder.py", line 337, in decode
obj, end = self.raw_decode(s, idx=_w(s, 0).end())
File "C:\Program Files\Splunk\Python-3.7\lib\json\decoder.py", line 355, in raw_decode
raise JSONDecodeError("Expecting value", s, err.value) from None
json.decoder.JSONDecodeError: Expecting value: line 1 column 1 (char 0)
2020-02-25 15:30:14,022 [SplunkClient] DEBUG requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Connecting to: https://127.0.0.1:8089/servicesNS/nobody/splunk-business-flow/properties/cloud/server
2020-02-25 15:30:14,038 [SplunkClient] ERROR requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Failed to execute: https://127.0.0.1:8089/servicesNS/nobody/splunk-business-flow/properties/cloud/server Err: Expecting value: line 1 column 1 (char 0)
Traceback (most recent call last):
File "C:\Program Files\Splunk\etc\apps\splunk-business-flow\bin\splunkd_client.py", line 187, in __get_config_url
results[config_name]=json.loads(data)
File "C:\Program Files\Splunk\Python-3.7\lib\json__init.py", line 348, in loads
return _default_decoder.decode(s)
File "C:\Program Files\Splunk\Python-3.7\lib\json\decoder.py", line 337, in decode
obj, end = self.raw_decode(s, idx=_w(s, 0).end())
File "C:\Program Files\Splunk\Python-3.7\lib\json\decoder.py", line 355, in raw_decode
raise JSONDecodeError("Expecting value", s, err.value) from None
json.decoder.JSONDecodeError: Expecting value: line 1 column 1 (char 0)
2020-02-25 15:30:14,039 [SplunkClient] DEBUG requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Connecting to: https://127.0.0.1:8089/servicesNS/nobody/splunk-business-flow/properties/sbf/server/url_prod
2020-02-25 15:30:14,048 [RegisterCommand] INFO requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Checking cloud server health
2020-02-25 15:30:14,049 [SplunkClient] DEBUG requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Connecting to: https://127.0.0.1:8089/servicesNS/nobody/splunk-business-flow/properties/sbf/server/url_prod
2020-02-25 15:30:14,057 [CloudHealthCommand] INFO requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e cloud server is https://eu.businessflowapp.splunk.com
2020-02-25 15:30:14,183 [RegisterCommand] INFO requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Cloud server health OK: https://eu.businessflowapp.splunk.com
2020-02-25 15:30:14,184 [RegisterCommand] INFO requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Cloud Server for registration: https://eu.businessflowapp.splunk.com
2020-02-25 15:30:14,184 [RegisterCommand] INFO requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Starting read of public key
2020-02-25 15:30:14,195 [RegisterCommand] INFO requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Read public key
2020-02-25 15:30:15,384 [Encryption] INFO Error with unlink: C:\WINDOWS\TEMP\tmprb_r6mxl
2020-02-25 15:30:15,385 [Encryption] INFO Error with unlink: C:\WINDOWS\TEMP\tmprb_r6mxl
2020-02-25 15:30:15,385 [SBFRestManager] ERROR requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e ('register error during encryption/decryption', EncryptionException('Error with decrypt', TypeError("a bytes-like object is required, not 'str'")))
Traceback (most recent call last):
File "C:\Program Files\Splunk\etc\apps\splunk-business-flow\bin\encryption.py", line 156, in decrypt
openssl_status=self.call_openssl(['aes-256-cbc','-d','-salt','-K',key,'-iv',init_vector,'-in',temp_file_in.name,'-out',temp_file_out.name])
File "C:\Program Files\Splunk\etc\apps\splunk-business-flow\bin\encryption.py", line 174, in call_openssl
return call(['{}/bin/splunk'.format(self.splunk_home),'cmd','openssl']+args)
File "C:\Program Files\Splunk\Python-3.7\lib\subprocess.py", line 323, in call
with Popen(*popenargs, **kwargs) as p:
File "C:\Program Files\Splunk\Python-3.7\lib\subprocess.py", line 775, in __init_
restore_signals, start_new_session)
File "C:\Program Files\Splunk\Python-3.7\lib\subprocess.py", line 1119, in _execute_child
args = list2cmdline(args)
File "C:\Program Files\Splunk\Python-3.7\lib\subprocess.py", line 530, in list2cmdline
needquote = (" " in arg) or ("\t" in arg) or not arg
TypeError: a bytes-like object is required, not 'str'
During handling of the above exception, another exception occurred:
Traceback (most recent call last):
File "C:\Program Files\Splunk\etc\apps\splunk-business-flow\bin\register_command.py", line 80, in _cloud_register
result,content,resp_decrypted=self.cloud_client.post(url,body)
File "C:\Program Files\Splunk\etc\apps\splunk-business-flow\bin\cloud_client.py", line 24, in post
decrypted=self.encryption.decrypt(resp['msg'],self.cja_priv,py23_decode(resp['key']),self.pem_password)
File "C:\Program Files\Splunk\etc\apps\splunk-business-flow\bin\encryption.py", line 162, in decrypt
raise EncryptionException("Error with decrypt",ex)
encryption.EncryptionException: ('Error with decrypt', TypeError("a bytes-like object is required, not 'str'"))
During handling of the above exception, another exception occurred:
Traceback (most recent call last):
File "C:\Program Files\Splunk\etc\apps\splunk-business-flow\bin\sbf_rest_manager.py", line 55, in handle
return RegisterCommand(dependencies).execute()
File "C:\Program Files\Splunk\etc\apps\splunk-business-flow\bin\register_command.py", line 57, in execute
returned_tenant_id,registration_id,warning=self._cloud_register(register_payload)
File "C:\Program Files\Splunk\etc\apps\splunk-business-flow\bin\register_command.py", line 101, in _cloud_register
raise RegisterEndpointException(CJAResponse.STATUS_ERROR_INTERNAL,'register error during encryption/decryption',ex)
register_command.RegisterEndpointException: ('register error during encryption/decryption', EncryptionException('Error with decrypt', TypeError("a bytes-like object is required, not 'str'")))
2020-02-25 15:30:20,960 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 15:30:21,024 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2_CA_CERTS): None
2020-02-25 15:30:21,044 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 15:30:21,124 [SplunkClient] INFO requestID:ebeb1264-e60c-441d-9220-cfad89b0abe6 PEM file not found in KV store, read PEM file locally
2020-02-25 15:30:21,143 [SplunkClient] ERROR requestID:ebeb1264-e60c-441d-9220-cfad89b0abe6 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 15:30:21,143 [SBFRestManager] INFO requestID:ebeb1264-e60c-441d-9220-cfad89b0abe6 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem
2020-02-25 15:30:21,143 [SBFRestManager] INFO requestID:ebeb1264-e60c-441d-9220-cfad89b0abe6 Requesting "/deployment_check" endpoint
2020-02-25 15:30:21,145 [DeploymentCheck] INFO requestID:ebeb1264-e60c-441d-9220-cfad89b0abe6 Starting deployment check
2020-02-25 15:30:23,753 [DeploymentCheck] INFO requestID:ebeb1264-e60c-441d-9220-cfad89b0abe6 {
"nodeName": "T470-PF0Y56UA",
"results": [
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://us.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 14:30:20 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://us.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://eu.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 14:30:20 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://eu.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://apac.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 14:30:21 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://apac.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {},
"isError": false,
"testName": "Testing app install folder permissions"
}
]
}*
Hi! Please upload your logs so the team can review and troubleshoot. If you are receiving an error, there should be a link to "Send report to Splunk" or something like that. You can also upload logs by changing the end of your url "app/splunk-business-flow/home" to "app/splunk-business-flow/diag"