All Apps and Add-ons

Error while installing Oracle Cloud Infrastructure (OCI) Logging Addon

yigaloz
Loves-to-Learn

Hello,

When trying to install this from my Splunk Enterprise (In my Windows10 client) I'm getting:

Unable to initialize modular input "oci_logging" defined in the app "TA-oci-logging-addon": Introspecting scheme=oci_logging: script running failed (exited with code 1)..

Labels (1)
Tags (1)
0 Karma

luizlimapg
Path Finder

Hi @yigaloz,

What helped me identify errors in the configuration of this addon was enabling debug logging by editing the file $SPLUNK_HOME/etc/apps/TA-oci-logging-addon/bin/oci_logging.py, changing the string ERROR to DEBUG on line 42. Then restart Splunk.

You can check the logs using the query:
index=_internal source=*oci_logging.log

Another possibility would be to install a previous version of the addon, which might work.

0 Karma

vrichards
Splunk Employee
Splunk Employee

Currently, the Oracle Cloud Infrastructure (OCI) Logging Addon needs to be installed on a Linux-based instance, a Windows client will result in the schema error.

 

0 Karma

vrichards
Splunk Employee
Splunk Employee

Can you please add which version of the addon you're running?

0 Karma

yigaloz
Loves-to-Learn
0 Karma

PickleRick
SplunkTrust
SplunkTrust

Do you get it right after installing the addon or after you configure it? You should check _internal index for details but I suspect it might be one of those badly written addons which comes with inputs enabled by default so it's trying to run the input with no configuration and fails.

0 Karma

yigaloz
Loves-to-Learn

Thank you for you response,

I'm getting this error right after the installation is finished. I do see the Addon in the apps list but I can't see it in the Data Inputs section.

By the way, the installation took some time so I had to increase the splunkdConnectionTimeout in web.conf (It is also mentioned under the troubleshooting tab of the Addon)

0 Karma

VKk1820
Observer

Any luck after that with the error

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...