All Apps and Add-ons

SAS Token Encyryption Errors

pkeller
Contributor

When using the app on a heavy forwarder to configure a Storage Account with a SAS token we're getting the following error. We've tried generating 2 different SAS keys and yet we still get the same Splunk rejection. The token is valid, yet Splunk appears to be incapable of handling it.

We're trying to first set this up under Configuration -> Add Azure Storage Account

The token generated is formatted like the string below ...

?sv=YYYY-MM-DD&sig=xx9xx22%2xX1x0xXxXxx%2xxXXXx0XXXxXxxxXXx00xxXX%3D&se=YYYY-YY-YYTNN%3x00%3c00x&srt=sco&ss=bfqt&sp=rl

alt text

0 Karma

pkeller
Contributor

This is now resolved. I did a fresh install of the Add-On and went through the storage account provisioning again and everything worked fine. This likely was due to my having copied an already configured app from our test environment to the production environment and that decryption was probably expecting a different secret key.

0 Karma
Get Updates on the Splunk Community!

See just what you’ve been missing | Observability tracks at Splunk University

Looking to sharpen your observability skills so you can better understand how to collect and analyze data from ...

Weezer at .conf25? Say it ain’t so!

Hello Splunkers, The countdown to .conf25 is on-and we've just turned up the volume! We're thrilled to ...

How SC4S Makes Suricata Logs Ingestion Simple

Network security monitoring has become increasingly critical for organizations of all sizes. Splunk has ...