All Apps and Add-ons

Splunk Add-on for EMC VNX: How do I resolve tags.conf errors "Value in stanza [eventtype=..]...not URI encoded"?

Explorer

How do I resolve this tags.conf problem?

[root@splunk-122 ~]# /root/splunk/bin/splunk restart
Stopping splunkd...
Shutting down.  Please wait, as this may take a few minutes.
...                                                        [  OK  ]
Stopping splunk helpers...
                                                           [  OK  ]
Done.

Splunk> Take the sh out of IT.

Checking prerequisites...
        Checking http port [8000]: open
        Checking mgmt port [8089]: open
        Checking appserver port [127.0.0.1:8065]: open
        Checking kvstore port [8191]: open
        Checking configuration...  Done.
        Checking critical directories...        Done
        Checking indexes...
                Validated: _audit _internal _introspection _thefishbucket history main summary
        Done
        Checking filesystem compatibility...  Done
        Checking conf files for problems...
                Value in stanza [eventtype=vnx:block:processorPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 3 not URI encoded: eventtype = vnx:block:processorPerf
                Value in stanza [eventtype=vnx:block:drivePerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 7 not URI encoded: eventtype = vnx:block:drivePerf
                Value in stanza [eventtype=vnx:block:devicePerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 11 not URI encoded: eventtype = vnx:block:devicePerf
                Value in stanza [eventtype=vnx:file:systemCachePerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 15 not URI encoded: eventtype = vnx:file:systemCachePerf
                Value in stanza [eventtype=vnx:file:systemPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 19 not URI encoded: eventtype = vnx:file:systemPerf
                Value in stanza [eventtype=vnx:file:fileSystemPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 23 not URI encoded: eventtype = vnx:file:fileSystemPerf
                Value in stanza [eventtype=vnx:file:diskVolumePerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 27 not URI encoded: eventtype = vnx:file:diskVolumePerf
                Value in stanza [eventtype=vnx:file:netDevicePerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 31 not URI encoded: eventtype = vnx:file:netDevicePerf
                Value in stanza [eventtype=vnx:file:cifsPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 35 not URI encoded: eventtype = vnx:file:cifsPerf
                Value in stanza [eventtype=vnx:file:cifsServerPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 39 not URI encoded: eventtype = vnx:file:cifsServerPerf
                Value in stanza [eventtype=vnx:file:cifsClientPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 43 not URI encoded: eventtype = vnx:file:cifsClientPerf
                Value in stanza [eventtype=vnx:file:cifsUserPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 47 not URI encoded: eventtype = vnx:file:cifsUserPerf
                Value in stanza [eventtype=vnx:file:cifsOpsPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 51 not URI encoded: eventtype = vnx:file:cifsOpsPerf
                Value in stanza [eventtype=vnx:file:nfsPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 55 not URI encoded: eventtype = vnx:file:nfsPerf
                Value in stanza [eventtype=vnx:file:nfsExportPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 59 not URI encoded: eventtype = vnx:file:nfsExportPerf
                Value in stanza [eventtype=vnx:file:nfsClientPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 63 not URI encoded: eventtype = vnx:file:nfsClientPerf
                Value in stanza [eventtype=vnx:file:nfsUserPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 67 not URI encoded: eventtype = vnx:file:nfsUserPerf
                Value in stanza [eventtype=vnx:file:nfsGroupPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 71 not URI encoded: eventtype = vnx:file:nfsGroupPerf
                Value in stanza [eventtype=vnx:file:nfsOpsPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 75 not URI encoded: eventtype = vnx:file:nfsOpsPerf
                Value in stanza [eventtype=vnx:block:systemOs] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 81 not URI encoded: eventtype = vnx:block:systemOs
                Value in stanza [eventtype=vnx:block:systemCpu] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 85 not URI encoded: eventtype = vnx:block:systemCpu
                Value in stanza [eventtype=vnx:block:systemMemory] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 89 not URI encoded: eventtype = vnx:block:systemMemory
                Value in stanza [eventtype=vnx:block:systemInventory] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 93 not URI encoded: eventtype = vnx:block:systemInventory
                Value in stanza [eventtype=vnx:block:device] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 97 not URI encoded: eventtype = vnx:block:device
                Value in stanza [eventtype=vnx:block:drive] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 102 not URI encoded: eventtype = vnx:block:drive
                Value in stanza [eventtype=vnx:block:raidGroup] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 107 not URI encoded: eventtype = vnx:block:raidGroup
                Value in stanza [eventtype=vnx:block:storagePool] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 112 not URI encoded: eventtype = vnx:block:storagePool
                Value in stanza [eventtype=vnx:file:fileSystem] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 117 not URI encoded: eventtype = vnx:file:fileSystem
                Value in stanza [eventtype=vnx:file:checkpoint] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 122 not URI encoded: eventtype = vnx:file:checkpoint
                Value in stanza [eventtype=vnx:file:vpfs] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 127 not URI encoded: eventtype = vnx:file:vpfs
                Value in stanza [eventtype=vnx:file:storagePool] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 132 not URI encoded: eventtype = vnx:file:storagePool
                Value in stanza [eventtype=vnx:file:disk] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 137 not URI encoded: eventtype = vnx:file:disk
                Value in stanza [eventtype=vnx:file:userQuota] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 142 not URI encoded: eventtype = vnx:file:userQuota
                Value in stanza [eventtype=vnx:file:groupQuota] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 147 not URI encoded: eventtype = vnx:file:groupQuota
                Value in stanza [eventtype=vnx:file:treeQuota] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 152 not URI encoded: eventtype = vnx:file:treeQuota
                Your indexes and inputs configurations are not internally consistent. For more information, run 'splunk btool check --debug'
        Done
        Checking default conf files for edits...
        Validating installed files against hashes from '/root/splunk/splunk-6.3.0-aa7d4b1ccb80-linux-2.6-x86_64-manifest'
        All installed files intact.
        Done
All preliminary checks passed.

Starting splunk server daemon (splunkd)...
Done
                                                           [  OK  ]

Waiting for web server at http://127.0.0.1:8000 to be available.. Done


If you get stuck, we're here to help.
Look for answers here: http://docs.splunk.com

The Splunk web interface is at http://splunk-122.nosbizlab.local:8000

[root@splunk-122 ~]#


[root@splunk-122 splunk]# tail -f -n 0 ta_vnx.log data_loader.log splunkd.log |grep -e vnx -e VNX
==> ta_vnx.log <==
==> ta_vnx.log <==
2015-11-16 18:16:08,451 INFO 140255710451456 - Start VNX TA
2015-11-16 18:16:09,491 INFO 140255710451456 - No data collection for VNX is found in the inputs.conf. Do nothing and Quit the TA
11-16-2015 18:16:29.081 +0900 INFO  SpecFiles - Found external scheme definition for stanza "vnx_data_loader://" with 7 parameters: network_addr, network_addr2, username, password, platform, site, loglevel
11-16-2015 18:16:29.386 +0900 INFO  ModularInputs - Introspection setup completed for scheme "vnx_data_loader".
11-16-2015 18:16:29.504 +0900 INFO  ModularInputs - No stanzas found for scheme "vnx_data_loader" in inputs.conf at script (re)start.
11-16-2015 18:16:29.504 +0900 INFO  ExecProcessor - New scheduled exec process: python /root/splunk/etc/apps/Splunk_TA_emc-vnx/bin/vnx_data_loader.py
==> ta_vnx.log &<==
2015-11-16 18:16:32,206 INFO 139959737960192 - Start VNX TA
==> ta_vnx.log <==
2015-11-16 18:16:33,252 INFO 139959737960192 - No data collection for VNX is found in the inputs.conf. Do nothing and Quit the TA
==> ta_vnx.log <==
2015-11-16 18:17:32,219 INFO 140035310089984 - Start VNX TA
2015-11-16 18:17:33,262 INFO 140035310089984 - No data collection for VNX is found in the inputs.conf. Do nothing and Quit the TA
1 Solution

Splunk Employee
Splunk Employee

Hi, this is a known bug introduced by more aggressive error-checking in the core; we have it on the backlog for fixing, but haven't scheduled it.

View solution in original post

0 Karma

To resolve the "not URL encoded" error, modify your $SPLUNKHOME/etc/apps/SplunkTA_emc-vnx/default/tags.conf and change all ":" (colon) to "%3A" -- %3A is the URL encoded representation for the colon. Until Splunk fixes the aggressive error checking, this will shut up the annoying error.

In vim edit mode:

:%s/:/\%3A/g

To resolve the "No data collection for VNX is found in the inputs.conf. Do nothing and Quit the TA" error, you need to modify your $SPLUNKHOME/etc/apps/SplunkTA_emc-vnx/local/inputs.conf to specify the IP address and user credential needed to read your EMC VNX. It looks like this:

[vnx_data_loader://EMC_GUID]
network_addr = x.y.z.zz
username = plaintextusername
password = plaintextpassword
platform = VNX Block or File

Splunk Employee
Splunk Employee

Hi, this is a known bug introduced by more aggressive error-checking in the core; we have it on the backlog for fixing, but haven't scheduled it.

View solution in original post

0 Karma

New Member

I'm having the same issue six months later:
No data collection for VNX is found in the inputs.conf. Do nothing and Quit the TA

Can anybody recommend a way to work around this bug?

0 Karma

Explorer

I understand what you wrote. Thank you very much for your kindeness.

0 Karma