I am running version 3.0.1 of the Microsoft Azure Add-on for Splunk on a single Splunk Enterprise server running version 8.0.1 in a Ubuntu Linux physical server. Sometime in the past two weeks the Azure add-on stopped pulling in data. Splunk is displaying an error message that states: Unable to initialize modular input "azure_virtual_network" defined in the app "TA-MS-AAD": Introspecting scheme=azure_virtual_network: script running failed (exited with code 1).. I've tried restarting Splunk and the server as well as overwriting the app with a fresh download from Splunkbase.
1) can you test new TA On different machine?
if new TA works in different machine.
2) Can you delete existing TA and delete checkpoints available at $SPLUNK_HOME/var/lib/splunk/modinputs/<taname>
3) restart splunkd
4) install TA again and configure new inputs and check.
Any idea what fixed this error?
i dont see any under modinouts
Was it working before?
if yes, did you remember making any changed to TA.
can you set logging level to debug and share logs?
Yes, it was working previously.
The only change I made was updating the add-on at some point (I don't remember when).
I've set the logs to debug but currently the logs are empty.
I had several inputs and two seperate accounts configured previously.
The Inputs and Configuration screens in the app now just show the headers and a spinning loading bar. I think I've been using the app with no issues for at least 18 months...
1) can you test new TA On different machine?
if new TA works in different machine.
2) Can you delete existing TA and delete checkpoints available at $SPLUNK_HOME/var/lib/splunk/modinputs/<taname>
3) restart splunkd
4) install TA again and configure new inputs and check.
The app works properly now. Thanks
Unable to initialize modular input "azure_virtual_network" defined in the app "TA-MS-AAD": Introspecting scheme=azure_virtual_network: script running failed (exited with code 1)..