I have installed EMC Isilon add-on on my Heavy Forwarder and tried setting it up, but it always ends up throwing error 'Encountered the following error while trying to update: Error while posting to url=/servicesNS/nobody/TA_EMC-Isilon/isiloncustom/isilonendpoint/setupentity'.
Upon checking the logs from /opt/splunk/var/log/isilon , i am getting several errors as below,
'EMC Isilon Error: HTTP Request error for endpoint : No JSON object could be decoded'
'EMC Isilon INFO: Password Entity Not found for given host and given user in splunk, so creating new entity'
'EMC Isilon Error: [HTTP 401] Client is not authenticated'
'EMC Isilon Error: HTTP Request error for endpoint : HTTPSConnectionPool(host='x.x.x.x', port=8080): Max retries exceeded with url: /session/1/session (Caused by : [Errno 111] Connection refused)'
'EMC Isilon Error: index isilon does not exist' : (For this i did workaround as suugested in this answer "https://answers.splunk.com/answers/507932/emc-isilon-app-and-add-on-for-splunk-enterprise-ho.html")
I have even tried the ultimate root user to authenticate but still getting the above errors.
Also one thing i noticed is there are 2 compulsory ways that isilon logs are to be taken, 1 via the syslog(isilon to splunk) and 2 the API calls(splunk to isilon) is this right?
Any help would be appreciated
Can someone help me with the steps that needs to be taken at configuration at Isilon source end and details that i need to co?
I have installed the add-on on the forwarder and search head and got stuck with the configuration.
This is also happening as I attempt to configure the app. As I look at the local directory of the app, i don't see a username/password for this entity. I'm bad at python so i'm not sure of everything the setup page is supposed to do, but I took the default isilonappsetup.conf file and put in there answers to the username, password and index values, to no avail.
Thanks for the future assist!