All Apps and Add-ons

Gsuite for Splunk script error

bcyates
Communicator

We have followed steps to configure GSuite Input Add-on. The authorize portion of the setup works just fine, but the only data indexed are error messages that say "Expected string or buffer" on line 101 of the ga.py script. Not sure how to troubleshoot past this point as I'm not much of a developer and do not know what that error message means.

tpetersonalpine
Explorer

I have to eat my words

[ga://token]
disabled = false
domain = dev-company.com
extraconfig = {}
index = gsuite_glbl
interval = 3600

proxy_name = not_configured

servicename = report:token

Once I changed domain to domain = dev.company.com I got it working
So to answer my own question: I have token working!

0 Karma

tpetersonalpine
Explorer

Still seeing this with 1.2.3 I think there's a bug here. Anyone able to see token logs with the latest code?

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

email me with better specifics. version 1.2.3 doesn't have that line at 101..... or find me on slack.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Line 101 of version 1.2.1 deals with the encrypted credential store. I will make logging better around that section, but if it didn't find a string, it is most likely a None type, which means your credentials didn't save correctly. Delete any google credentials from the store, and re-authorize.

0 Karma

bcyates
Communicator

Bump. Anyone with an idea?

0 Karma

praneshjan
Explorer

Hi bcyates. Did you find the solution for this issue yet? Even we are facing the same. Please share if this issue was solved. It would be very helpful.

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Hi! App author here. What version of GSuite?

0 Karma

bcyates
Communicator

Hi! version = 1.2.1of IA-GSuiteforSplunk on a Heavy Forwarder, version 7.0.4

0 Karma

alacercogitatus
SplunkTrust
SplunkTrust

Find me tomorrow on Slack. I think you are second on that error, so want some additional info.

splk.it/slack Thanks!

0 Karma

bcyates
Communicator

I've submitted my info. Just waiting for an approval I supppose

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

How much can you really learn in 3 minutes?

Observability can certainly be hard to understand – there's a lot of jargon and buzzwords and it seems to ...

Event Series: The Agentic SOC: Trust Before Autonomy

AI is fundamentally changing security operations, but true progress requires more than just automation—it ...

Free Professional Services for .conf26 Attendees

This year at .conf26, we are doing something a little different. We are bringing the best minds from ...