All Apps and Add-ons

Receiving many error messages for python scripts from splunk_ta_paloalto.

markhill1
Path Finder

Hi Palo people, we are seeing thousands of errors from the various python scripts within the Palo Alto TA. (V6.1.1).
Examples:

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py"   File "/opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/solnlib/packages/splunklib/binding.py", line 287, in wrapper

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py"   File "/opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/modinput_wrapper/base_modinput.py", line 113, in stream_events

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py"   File "/opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/splunktaucclib/global_config/configuration.py", line 264, in load

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py"     self.parse_input_args(input_definition)

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py" HTTPError: HTTP 500 Internal Server Error -- {"messages":[{"type":"ERROR","text":"Cannot call handler 'Splunk_TA_paloalto_account' due to missing script 'Splunk_TA_paloalto_rh_account.py'."}]}

These are just some examples there are more. We have it installed one of the Splunk Cloud instances we manage.
The errors are coming from the indexers. We asked for it to be installed on our ES search head.
We aren't using the TA to pull any data in, we are just using it for the props and transforms on the ES search head.
It is also installed on the on-prem HWF.
Can you please let us know how we may be able to fix this?
Thanks.

0 Karma
1 Solution

mdillon_splunk
Splunk Employee
Splunk Employee
  • Resolved by removing Splunk_TA_paloalto from the Indexers. Was not required there as was also installed on the on-prem HWF.

View solution in original post

0 Karma

mdillon_splunk
Splunk Employee
Splunk Employee
  • Resolved by removing Splunk_TA_paloalto from the Indexers. Was not required there as was also installed on the on-prem HWF.
0 Karma

markhill1
Path Finder

Thanks, I'll raise a case with cloud ops to get this done, thanks for the response.
I'll let you know what happens.
Cheers

0 Karma

panguy
Contributor

Try adding this to local/inputs.conf

[autofocus_export]
disabled = true
0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...