We have trialled using the Microsoft Cloud Services Add-On on a trial/dev Splunk Enterprise instance to figure out the process for importing and munging data from Azure Blob Storage . After some work, the process was figured out, and we then tried installing the Microsoft Cloud Services Add-On into our production SplunkCloud instance. Unfortunately the Add-On doesn't seem to function.. Once the Add-On has been installed, browsing to the App via the App list results in an almost blank page (regular Splunk header visible). Neither the "Inputs" or "Configuration" tab function, the "Search" page works, but I assume this is just a regular Splunk search page and has nothing to do specifically with the Add-On.
In my browsers developer console, looking at the network tab, I can see two GET requests to the Splunk_ta_mscs_mscs_* objects are getting a 500 Internal Server Error response code. Looking further into these requests, in the body of the 500 response, the response message is actually a 404:
Unexpected error " 'splunktaucclib.rest_handler.error.RestError'>"
from python handler: "REST Error
[404]: Not Found -- HTTP 404 Not Found
-- {"messages":[{"type":"ERROR","text":"Not
Found"}]}". See splunkd.log for more
details.
Unfortunately as this is a SplunkCloud instance, I do not have access to the splunkd.log (as far as I am aware). I have also tried removing the Add-On and reinstalling it, the same behaviour was observed both times.
The closest related issue I could find was this, however their issue was that they were using an unsupported version of Splunk. According to the Add-On page, we are using a supported version of Splunk (SplunkCloud, 8.0). The more detailed documentation doesn't actually specifically mention SplunkCloud support.
Web browser showing server error.
Application was installed 30 minutes before this page load of the app was attempted.
(The Apps configuration page also fails to load, cannot attach screenshot because maximum number of attachments reached for this post.)
I'm unsure if this is what you are looking for, but I'm pasting this response for a few questions about this add-on not loading.
If this is your issue, try this:
vi /opt/splunk/etc/apps/Splunk_TA_microsoft-cloudservices/bin/splunktamscs/ca_certs_locater.py
Look for TEMP_CERT_FILE_PATH
and update it to '/etc/pki/tls/certs/ca-bundle.crt'
TEMP_CERT_FILE_PATH = '/etc/pki/tls/certs/ca-bundle.crt'
Save the changes and restart Splunk
Please let us know if this works for you.
Hi Porares, no this doesn't work. As I initially stated, this is a SplunkCloud instance, I have no access to the underlying configs like you would if running Splunk Enterprise.
Hi Jeremyfer,
I work on Cloud Support and I am currently checking on a case with this issue. Have you opened a case with Support?
Hi @povares_splunk, sorry for the late response. We abandoned logging into Splunk because the add-on didn't work.
Well that's nice, Splunk deleted my embedded links because I'm new, maybe these will work.
The closest related issue.
https://answers.splunk.com/answers/548485/is-the-splunk-add-on-for-microsoft-cloud-services.html
The Add-On page
https://splunkbase.splunk.com/app/3110/
The more detailed documentation
https://docs.splunk.com/Documentation/AddOns/released/MSCloudServices/Hardwareandsoftwarerequirement...