All Apps and Add-ons

New issue with the Microsoft Azure addon for Splunk

chioverheaddoor
Explorer

I am running version 3.0.1 of the Microsoft Azure Add-on for Splunk on a single Splunk Enterprise server running version 8.0.1 in a Ubuntu Linux physical server.  Sometime in the past two weeks the Azure add-on stopped pulling in data.  Splunk is displaying an error message that states:  Unable to initialize modular input "azure_virtual_network" defined in the app "TA-MS-AAD": Introspecting scheme=azure_virtual_network: script running failed (exited with code 1)..  I've tried restarting Splunk and the server as well as overwriting the app with a fresh download from Splunkbase. 

0 Karma
1 Solution

thambisetty
SplunkTrust
SplunkTrust

1) can you test new TA On different machine?

if new TA works in different machine.

2) Can you delete existing TA and delete checkpoints available at $SPLUNK_HOME/var/lib/splunk/modinputs/<taname>
3) restart splunkd

4) install TA again and configure new inputs and check.

 

————————————
If this helps, give a like below.

View solution in original post

ShaggyDoe
New Member

Any idea what fixed this error?

i dont see any under modinouts

0 Karma

thambisetty
SplunkTrust
SplunkTrust

Was it working before?

if yes, did you remember making any changed to TA.

can you set logging level to debug and share logs?

————————————
If this helps, give a like below.

chioverheaddoor
Explorer

Yes, it was working previously.

The only change I made was updating the add-on at some point (I don't remember when).

I've set the logs to debug but currently the logs are empty.

I had several inputs and two seperate accounts configured previously.  

The Inputs and Configuration screens in the app now just show the headers and a spinning loading bar.  I think I've been using the app with no issues for at least 18 months...

0 Karma

thambisetty
SplunkTrust
SplunkTrust

1) can you test new TA On different machine?

if new TA works in different machine.

2) Can you delete existing TA and delete checkpoints available at $SPLUNK_HOME/var/lib/splunk/modinputs/<taname>
3) restart splunkd

4) install TA again and configure new inputs and check.

 

————————————
If this helps, give a like below.

chioverheaddoor
Explorer

The app works properly now.  Thanks

0 Karma

ShaggyDoe
New Member

Unable to initialize modular input "azure_virtual_network" defined in the app "TA-MS-AAD": Introspecting scheme=azure_virtual_network: script running failed (exited with code 1)..

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...