All Apps and Add-ons

Receiving many error messages for python scripts from splunk_ta_paloalto.

markhill1
Path Finder

Hi Palo people, we are seeing thousands of errors from the various python scripts within the Palo Alto TA. (V6.1.1).
Examples:

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py"   File "/opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/solnlib/packages/splunklib/binding.py", line 287, in wrapper

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py"   File "/opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/modinput_wrapper/base_modinput.py", line 113, in stream_events

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py"   File "/opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/splunktaucclib/global_config/configuration.py", line 264, in load

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py"     self.parse_input_args(input_definition)

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py" HTTPError: HTTP 500 Internal Server Error -- {"messages":[{"type":"ERROR","text":"Cannot call handler 'Splunk_TA_paloalto_account' due to missing script 'Splunk_TA_paloalto_rh_account.py'."}]}

These are just some examples there are more. We have it installed one of the Splunk Cloud instances we manage.
The errors are coming from the indexers. We asked for it to be installed on our ES search head.
We aren't using the TA to pull any data in, we are just using it for the props and transforms on the ES search head.
It is also installed on the on-prem HWF.
Can you please let us know how we may be able to fix this?
Thanks.

0 Karma
1 Solution

mdillon_splunk
Splunk Employee
Splunk Employee
  • Resolved by removing Splunk_TA_paloalto from the Indexers. Was not required there as was also installed on the on-prem HWF.

View solution in original post

0 Karma

mdillon_splunk
Splunk Employee
Splunk Employee
  • Resolved by removing Splunk_TA_paloalto from the Indexers. Was not required there as was also installed on the on-prem HWF.
0 Karma

markhill1
Path Finder

Thanks, I'll raise a case with cloud ops to get this done, thanks for the response.
I'll let you know what happens.
Cheers

0 Karma

panguy
Contributor

Try adding this to local/inputs.conf

[autofocus_export]
disabled = true
0 Karma
Get Updates on the Splunk Community!

App Building 101 - Build Your First App!

WATCH RECORDING NOW   Tech Talk: App Dev Edition Splunk has tons of out-of-the-box functionality, and you’ve ...

Introducing support for Amazon Data Firehose in Splunk Edge Processor

We’re excited to announce a powerful update to Splunk Data Management with added support for Amazon Data ...

The Observability Round-Up: September 2024

What’s up Splunk Community! Welcome to the latest edition of the Observability Round-Up, a monthly series in ...