All Apps and Add-ons

Microsoft Azure Active Directory Add-on for Splunk: Customized key cannot be found

wstarowicz
Path Finder

Hi, for a few days I haven't gotten any logs.
After enabling debug, I see something like " Customized key cannot be found".
What does it mean?

schelms
Engager

I started receiving this error recently. It seems that when I have 2 or more inputs (either Signins, Audit, or Users) then I get this error. However, if I delete all but a single input then it works. So temporarily I can only have one working input.

I think the issue may have to do with the rotation of the Auth token when making the API call but that is just my guess.

0 Karma

jaxjohnny2000
Builder

maybe. I have the same issue after my initial key expired. It does not like the second one.

0 Karma

jaxjohnny2000
Builder

Problem no longer exists after upgrading to 2.0.0 for me.

0 Karma

brianbye
Explorer

Im having the same issue. Anyone figure out a permanent solution?

0 Karma

jaxjohnny2000
Builder

Same issue here. My Client Certificate expired. I created a new one. Then may other errors, but this is the most pervasive.

tid=MainThread file=setup_util.py:log_info:114 | Customized key can not be found

0 Karma

ylucena
Explorer

I am having the same problem! Did you guys figured that out?

0 Karma

jwalzerpitt
Influencer

+1 as also having the issue

Any idea as to why the issue and if a solution exists?

0 Karma

DavidHourani
Super Champion

Hi @wstarowicz, what errors do you have exactly in _internal regarding this issue, could you give us some outputs here ?

0 Karma

wstarowicz
Path Finder

It's a bit strange. Earlier I had 429 (since few days). These started to appear (as INFO) after few disabling/enabling of the input. Now it started working (logs are downloaded). So this is rather question now what does it mean.

2019-06-21 11:52:40,409 DEBUG pid=11844 tid=MainThread file=connectionpool.py:_new_conn:809 | Starting new HTTPS connection (1): login.microsoftonline.com
2019-06-21 11:52:40,690 DEBUG pid=11844 tid=MainThread file=connectionpool.py:_make_request:400 | https://login.microsoftonline.com:443 "POST /tenant_id/oauth2/v2.0/token HTTP/1.1" 200 1516
2019-06-21 11:52:40,693 DEBUG pid=11844 tid=MainThread file=base_modinput.py:log_debug:286 | Sign-in URL used: https://graph.microsoft.com/beta/auditLogs/signIns?$orderby=createdDateTime&$filter=createdDateTime+...
2019-06-21 11:52:40,693 INFO pid=11844 tid=MainThread file=setup_util.py:log_info:114 | Customized key can not be found

0 Karma

DavidHourani
Super Champion

Which Splunk version are you using ? Maybe there was an incompatibility. Also did you restart Splunk after installing the ad-on ?

0 Karma

wstarowicz
Path Finder

Hi, yes I did. I'm running version 7.2.4.

0 Karma

DavidHourani
Super Champion

That should be okay, it's supported : Splunk Versions: 7.3, 7.2, 7.1, 7.0, 6.6. Should be some bug that got flushed with the enable-disable.

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...