All Apps and Add-ons

Getting error with Microsoft Azure Add on for Splunk: Unable to initialize modular input "azure_event_hub" defined in the app TA-MS-AAD.

jabbene00
New Member

Just installed both versions of Microsoft Azure Add on for Splunk on Heavy forwarder.

When I open the inputs area nothing happens, just spins. Eventually, the following error shows up in messages:

Unable to initialize modular input "azure_event_hub" defined in the app "TA-MS-AAD": Introspecting scheme=azure_event_hub: script running failed (exited with code 1)

Any assistance would be great.

0 Karma

cnuguri_ncc
Path Finder

I have this error on Mac OS too, Tried on Splunk 8.0 and  8.1, with Add-on 3.0.1. 😐

Edit:  Actually my error is slightly different, I get the below when adding the input, and input is not created

Argument validation for scheme=azure_event_hub failed: The script returned with exit status 1.

 

0 Karma

jconger
Splunk Employee
Splunk Employee

The Event Hub input does not currently work on Windows. See the About platforms section here -> https://splunkbase.splunk.com/app/3757/#/details

It has to do with the Python library used to ingest Event Hub data. A new version is in development for Splunk 8 and should include Windows support for the Event Hub input as well.

0 Karma

jconger
Splunk Employee
Splunk Employee

What OS is your HWF?

0 Karma

jabbene00
New Member

Windows 2016

0 Karma

jabbene00
New Member

HF is
Splunk Enterprise
Version:
8.0.3
Build:
a6754d8441bf

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Developer Spotlight with Denis Gladkikh

From Splunk Engineer to Kubernetes App Builder Denis GladkikhWhat happens when a lifelong developer turns a ...

Governing Enterprise AI, Bringing Cisco Telemetry Home, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...