All Apps and Add-ons

Gsuite for Splunk script error

bcyates
Communicator

We have followed steps to configure GSuite Input Add-on. The authorize portion of the setup works just fine, but the only data indexed are error messages that say "Expected string or buffer" on line 101 of the ga.py script. Not sure how to troubleshoot past this point as I'm not much of a developer and do not know what that error message means.

tpetersonalpine
Explorer

I have to eat my words

[ga://token]
disabled = false
domain = dev-company.com
extraconfig = {}
index = gsuite_glbl
interval = 3600

proxy_name = not_configured

servicename = report:token

Once I changed domain to domain = dev.company.com I got it working
So to answer my own question: I have token working!

0 Karma

tpetersonalpine
Explorer

Still seeing this with 1.2.3 I think there's a bug here. Anyone able to see token logs with the latest code?

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

email me with better specifics. version 1.2.3 doesn't have that line at 101..... or find me on slack.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Line 101 of version 1.2.1 deals with the encrypted credential store. I will make logging better around that section, but if it didn't find a string, it is most likely a None type, which means your credentials didn't save correctly. Delete any google credentials from the store, and re-authorize.

0 Karma

bcyates
Communicator

Bump. Anyone with an idea?

0 Karma

praneshjan
Explorer

Hi bcyates. Did you find the solution for this issue yet? Even we are facing the same. Please share if this issue was solved. It would be very helpful.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Hi! App author here. What version of GSuite?

0 Karma

bcyates
Communicator

Hi! version = 1.2.1of IA-GSuiteforSplunk on a Heavy Forwarder, version 7.0.4

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Find me tomorrow on Slack. I think you are second on that error, so want some additional info.

splk.it/slack Thanks!

0 Karma

bcyates
Communicator

I've submitted my info. Just waiting for an approval I supppose

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In January, the Splunk Threat Research Team had one release of new security content via the Splunk ES Content ...

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...