All Apps and Add-ons

SAS Token Encyryption Errors

pkeller
Contributor

When using the app on a heavy forwarder to configure a Storage Account with a SAS token we're getting the following error. We've tried generating 2 different SAS keys and yet we still get the same Splunk rejection. The token is valid, yet Splunk appears to be incapable of handling it.

We're trying to first set this up under Configuration -> Add Azure Storage Account

The token generated is formatted like the string below ...

?sv=YYYY-MM-DD&sig=xx9xx22%2xX1x0xXxXxx%2xxXXXx0XXXxXxxxXXx00xxXX%3D&se=YYYY-YY-YYTNN%3x00%3c00x&srt=sco&ss=bfqt&sp=rl

alt text

0 Karma

pkeller
Contributor

This is now resolved. I did a fresh install of the Add-On and went through the storage account provisioning again and everything worked fine. This likely was due to my having copied an already configured app from our test environment to the production environment and that decryption was probably expecting a different secret key.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...