All Apps and Add-ons

Error while installing Oracle Cloud Infrastructure (OCI) Logging Addon

yigaloz
Loves-to-Learn

Hello,

When trying to install this from my Splunk Enterprise (In my Windows10 client) I'm getting:

Unable to initialize modular input "oci_logging" defined in the app "TA-oci-logging-addon": Introspecting scheme=oci_logging: script running failed (exited with code 1)..

Labels (1)
Tags (1)
0 Karma

luizlimapg
Path Finder

Hi @yigaloz,

What helped me identify errors in the configuration of this addon was enabling debug logging by editing the file $SPLUNK_HOME/etc/apps/TA-oci-logging-addon/bin/oci_logging.py, changing the string ERROR to DEBUG on line 42. Then restart Splunk.

You can check the logs using the query:
index=_internal source=*oci_logging.log

Another possibility would be to install a previous version of the addon, which might work.

0 Karma

vrichards
Splunk Employee
Splunk Employee

Currently, the Oracle Cloud Infrastructure (OCI) Logging Addon needs to be installed on a Linux-based instance, a Windows client will result in the schema error.

 

0 Karma

vrichards
Splunk Employee
Splunk Employee

Can you please add which version of the addon you're running?

0 Karma

yigaloz
Loves-to-Learn
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Do you get it right after installing the addon or after you configure it? You should check _internal index for details but I suspect it might be one of those badly written addons which comes with inputs enabled by default so it's trying to run the input with no configuration and fails.

0 Karma

yigaloz
Loves-to-Learn

Thank you for you response,

I'm getting this error right after the installation is finished. I do see the Addon in the apps list but I can't see it in the Data Inputs section.

By the way, the installation took some time so I had to increase the splunkdConnectionTimeout in web.conf (It is also mentioned under the troubleshooting tab of the Addon)

0 Karma

VKk1820
Observer

Any luck after that with the error

0 Karma
Get Updates on the Splunk Community!

Developer Spotlight with Brett Adams

In our third Spotlight feature, we're excited to shine a light on Brett—a Splunk consultant, innovative ...

Index This | What can you do to make 55,555 equal 500?

April 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this ...

Say goodbye to manually analyzing phishing and malware threats with Splunk Attack ...

In today’s evolving threat landscape, we understand you’re constantly bombarded with phishing and malware ...