All Apps and Add-ons

Receiving many error messages for python scripts from splunk_ta_paloalto.

markhill1
Path Finder

Hi Palo people, we are seeing thousands of errors from the various python scripts within the Palo Alto TA. (V6.1.1).
Examples:

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py"   File "/opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/solnlib/packages/splunklib/binding.py", line 287, in wrapper

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py"   File "/opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/modinput_wrapper/base_modinput.py", line 113, in stream_events

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py"   File "/opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/splunktaucclib/global_config/configuration.py", line 264, in load

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py"     self.parse_input_args(input_definition)

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py" HTTPError: HTTP 500 Internal Server Error -- {"messages":[{"type":"ERROR","text":"Cannot call handler 'Splunk_TA_paloalto_account' due to missing script 'Splunk_TA_paloalto_rh_account.py'."}]}

These are just some examples there are more. We have it installed one of the Splunk Cloud instances we manage.
The errors are coming from the indexers. We asked for it to be installed on our ES search head.
We aren't using the TA to pull any data in, we are just using it for the props and transforms on the ES search head.
It is also installed on the on-prem HWF.
Can you please let us know how we may be able to fix this?
Thanks.

0 Karma
1 Solution

mdillon_splunk
Splunk Employee
Splunk Employee
  • Resolved by removing Splunk_TA_paloalto from the Indexers. Was not required there as was also installed on the on-prem HWF.

View solution in original post

0 Karma

mdillon_splunk
Splunk Employee
Splunk Employee
  • Resolved by removing Splunk_TA_paloalto from the Indexers. Was not required there as was also installed on the on-prem HWF.
0 Karma

markhill1
Path Finder

Thanks, I'll raise a case with cloud ops to get this done, thanks for the response.
I'll let you know what happens.
Cheers

0 Karma

panguy
Contributor

Try adding this to local/inputs.conf

[autofocus_export]
disabled = true
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...