All Apps and Add-ons

Receiving many error messages for python scripts from splunk_ta_paloalto.

Path Finder

Hi Palo people, we are seeing thousands of errors from the various python scripts within the Palo Alto TA. (V6.1.1).
Examples:

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py"   File "/opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/solnlib/packages/splunklib/binding.py", line 287, in wrapper

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py"   File "/opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/modinput_wrapper/base_modinput.py", line 113, in stream_events

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py"   File "/opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/splunktaucclib/global_config/configuration.py", line 264, in load

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py"     self.parse_input_args(input_definition)

ERROR ExecProcessor - message from "python /opt/splunk/etc/slave-apps/Splunk_TA_paloalto/bin/autofocus_export.py" HTTPError: HTTP 500 Internal Server Error -- {"messages":[{"type":"ERROR","text":"Cannot call handler 'Splunk_TA_paloalto_account' due to missing script 'Splunk_TA_paloalto_rh_account.py'."}]}

These are just some examples there are more. We have it installed one of the Splunk Cloud instances we manage.
The errors are coming from the indexers. We asked for it to be installed on our ES search head.
We aren't using the TA to pull any data in, we are just using it for the props and transforms on the ES search head.
It is also installed on the on-prem HWF.
Can you please let us know how we may be able to fix this?
Thanks.

0 Karma
1 Solution

Splunk Employee
Splunk Employee
  • Resolved by removing Splunk_TA_paloalto from the Indexers. Was not required there as was also installed on the on-prem HWF.

View solution in original post

0 Karma

Splunk Employee
Splunk Employee
  • Resolved by removing Splunk_TA_paloalto from the Indexers. Was not required there as was also installed on the on-prem HWF.

View solution in original post

0 Karma

Path Finder

Thanks, I'll raise a case with cloud ops to get this done, thanks for the response.
I'll let you know what happens.
Cheers

0 Karma

Contributor

Try adding this to local/inputs.conf

[autofocus_export]
disabled = true
0 Karma