All Apps and Add-ons
Highlighted

Microsoft Azure Active Directory Add-on for Splunk: Customized key cannot be found

Path Finder

Hi, for a few days I haven't gotten any logs.
After enabling debug, I see something like " Customized key cannot be found".
What does it mean?

Highlighted

Re: Microsoft Azure Active Directory Add-on for Splunk: Customized key cannot be found

SplunkTrust
SplunkTrust

Hi @wstarowicz, what errors do you have exactly in _internal regarding this issue, could you give us some outputs here ?

0 Karma
Highlighted

Re: Microsoft Azure Active Directory Add-on for Splunk: Customized key cannot be found

Path Finder

It's a bit strange. Earlier I had 429 (since few days). These started to appear (as INFO) after few disabling/enabling of the input. Now it started working (logs are downloaded). So this is rather question now what does it mean.

2019-06-21 11:52:40,409 DEBUG pid=11844 tid=MainThread file=connectionpool.py:_new_conn:809 | Starting new HTTPS connection (1): login.microsoftonline.com
2019-06-21 11:52:40,690 DEBUG pid=11844 tid=MainThread file=connectionpool.py:_make_request:400 | https://login.microsoftonline.com:443 "POST /tenant_id/oauth2/v2.0/token HTTP/1.1" 200 1516
2019-06-21 11:52:40,693 DEBUG pid=11844 tid=MainThread file=base_modinput.py:log_debug:286 | Sign-in URL used: https://graph.microsoft.com/beta/auditLogs/signIns?$orderby=createdDateTime&$filter=createdDateTime+...
2019-06-21 11:52:40,693 INFO pid=11844 tid=MainThread file=setup_util.py:log_info:114 | Customized key can not be found

0 Karma
Highlighted

Re: Microsoft Azure Active Directory Add-on for Splunk: Customized key cannot be found

SplunkTrust
SplunkTrust

Which Splunk version are you using ? Maybe there was an incompatibility. Also did you restart Splunk after installing the ad-on ?

0 Karma
Highlighted

Re: Microsoft Azure Active Directory Add-on for Splunk: Customized key cannot be found

Path Finder

Hi, yes I did. I'm running version 7.2.4.

0 Karma
Highlighted

Re: Microsoft Azure Active Directory Add-on for Splunk: Customized key cannot be found

SplunkTrust
SplunkTrust

That should be okay, it's supported : Splunk Versions: 7.3, 7.2, 7.1, 7.0, 6.6. Should be some bug that got flushed with the enable-disable.

0 Karma
Highlighted

Re: Microsoft Azure Active Directory Add-on for Splunk: Customized key cannot be found

Explorer

Im having the same issue. Anyone figure out a permanent solution?

0 Karma
Highlighted

Re: Microsoft Azure Active Directory Add-on for Splunk: Customized key cannot be found

Explorer

I am having the same problem! Did you guys figured that out?

0 Karma
Highlighted

Re: Microsoft Azure Active Directory Add-on for Splunk: Customized key cannot be found

Motivator

+1 as also having the issue

Any idea as to why the issue and if a solution exists?

0 Karma
Highlighted

Re: Microsoft Azure Active Directory Add-on for Splunk: Customized key cannot be found

Contributor

Same issue here. My Client Certificate expired. I created a new one. Then may other errors, but this is the most pervasive.

tid=MainThread file=setuputil.py:loginfo:114 | Customized key can not be found

0 Karma