All Apps and Add-ons

Receiving many error messages for python scripts from splunk_ta_paloalto.

markhill1
Path Finder

Hi Palo people, we are seeing thousands of errors from the various python scripts within the Palo Alto TA. (V6.1.1).
Examples:

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py"   File "/opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/solnlib/packages/splunklib/binding.py", line 287, in wrapper

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py"   File "/opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/modinput_wrapper/base_modinput.py", line 113, in stream_events

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py"   File "/opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/splunktaucclib/global_config/configuration.py", line 264, in load

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py"     self.parse_input_args(input_definition)

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py" HTTPError: HTTP 500 Internal Server Error -- {"messages":[{"type":"ERROR","text":"Cannot call handler 'Splunk_TA_paloalto_account' due to missing script 'Splunk_TA_paloalto_rh_account.py'."}]}

These are just some examples there are more. We have it installed one of the Splunk Cloud instances we manage.
The errors are coming from the indexers. We asked for it to be installed on our ES search head.
We aren't using the TA to pull any data in, we are just using it for the props and transforms on the ES search head.
It is also installed on the on-prem HWF.
Can you please let us know how we may be able to fix this?
Thanks.

0 Karma
1 Solution

mdillon_splunk
Splunk Employee
Splunk Employee
  • Resolved by removing Splunk_TA_paloalto from the Indexers. Was not required there as was also installed on the on-prem HWF.

View solution in original post

0 Karma

mdillon_splunk
Splunk Employee
Splunk Employee
  • Resolved by removing Splunk_TA_paloalto from the Indexers. Was not required there as was also installed on the on-prem HWF.
0 Karma

markhill1
Path Finder

Thanks, I'll raise a case with cloud ops to get this done, thanks for the response.
I'll let you know what happens.
Cheers

0 Karma

panguy
Contributor

Try adding this to local/inputs.conf

[autofocus_export]
disabled = true
0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...