All Apps and Add-ons

Modular input error on defender-atp-hunting

dyeyniyel
Explorer

I'm getting below error for the TA-defender-atp-hunting on our HF.

Unable to initialize modular input "defender_hunting_query" defined in the app "TA-defender-atp-hunting": Introspecting scheme=defender_hunting_query: script running failed (exited with code 1)..

splunkd logs

ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':  The script at path=/opt/splunk/etc/apps/TA-defender-atp-hunting/bin/TA_defender_atp_hunting_rh_defender_hunting_query.py has thrown an exception=Traceback (most recent call last)

10-06-2021 03:20:48.823 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':File "/opt/splunk/bin/runScript.py", line 82, in <module>
10-06-2021 03:20:48.823 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':exec(open(REAL_SCRIPT_NAME).read())
10-06-2021 03:20:48.823 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':File "<string>", line 4, in <module>
10-06-2021 03:20:48.823 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':File "/opt/splunk/etc/apps/TA-defender-atp-hunting/bin/ta_defender_atp_hunting/splunktaucclib/rest_handler/endpoint/validator.py", line 388
10-06-2021 03:20:48.823 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':except ValueError, exc:
10-06-2021 03:20:48.823 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':                       ^
10-06-2021 03:20:48.823 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':SyntaxError: invalid syntax
10-06-2021 03:20:48.824 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':Traceback (most recent call last):
10-06-2021 03:20:48.824 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':File "/opt/splunk/bin/runScript.py", line 82, in <module>
10-06-2021 03:20:48.824 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':exec(open(REAL_SCRIPT_NAME).read())
10-06-2021 03:20:48.824 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':File "<string>", line 4, in <module>
10-06-2021 03:20:48.824 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':File "/opt/splunk/etc/apps/TA-defender-atp-hunting/bin/ta_defender_atp_hunting/splunktaucclib/rest_handler/endpoint/validator.py", line 388
10-06-2021 03:20:48.824 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':except ValueError, exc:
10-06-2021 03:20:48.824 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':                       ^
10-06-2021 03:20:48.824 +0000 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python3.7 /opt/splunk/bin/runScript.py setup':SyntaxError: invalid syntax
10-06-2021 03:20:48.828 +0000 ERROR AdminManagerExternal - External handler failed with code '1' and output: ''.  See splunkd.log for stderr output.

I'm not able to access the defender atp hunting app via UI. Would anyone know how to resolve this issue? 

Thanks in advance!

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...