All Apps and Add-ons

Issue with Google Import/export when create key in service account settings.

CARLOSEMONTESP
Explorer

Hi.

Im having problems when create the key and put it in "Drop key here or choose file" the app makes nothing, even when i put the key manually in the inputs.conf in $SPLUNK_HOME/etc/apps/google_drive/local/inputs.conf.

Thanks in advance for any help.

LukeMurphey
Champion

There isn't much in your post to go on. Could you check a couple of things to help diagnose the issue?

First, check to see if the Javascript console shows any errors after you upload the key on the setup page. See here for details.

Second, check the logs in Splunk to see if it posts anything noteworthy:

index=_internal (service_account_keys AND sourcetype=splunk_web_service) OR (sourcetype=google_spreadsheet_modular_input)
0 Karma

CARLOSEMONTESP
Explorer

Hi Luke.

Thankis for helping.

The warning in Dev Console:

VM144:104 [Deprecation] Synchronous XMLHttpRequest on the main thread is deprecated because of its detrimental effects to the end user's experience. For more help, check https://xhr.spec.whatwg.org/.
send @ common.js:27
ajax @ common.js:26
uploadFile @ VM144:104
(anonymous) @ VM144:190
load (async)
handleUploadedFile @ VM144:173
dispatch @ common.js:25
elemData.handle @ common.js:25
VM144:121 Successfully added a service account key file
VM144:191 File successfully uploaded

The search throws this message:

index=_internal (service_account_keys AND sourcetype=splunk_web_service) OR (sourcetype=google_spreadsheet_modular_input)

2018-04-03 10:08:31,526 WARNING Unable to access the spreadsheet, make sure the service account has been granted access to this file; spreadsheet_title=Seguimiento de Abonos, help_url=http://lukemurphey.net/projects/splunk-google-docs/wiki/How_to_setup_app

0 Karma

CARLOSEMONTESP
Explorer

Important to mention, the email account only has permission to read the file, but if I take out the file from the "team unit" and place it in a normal unit, it works perfectly.

0 Karma

CARLOSEMONTESP
Explorer

By the way, the file is in a Google Drive Team Unit, and have the permission for the mail address specified in the service account

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...