All Apps and Add-ons

Website Monitoring App stops the splunk service

Ashwini008
Builder

Hi All,

I am using Website Monitoring in one of our HF.But whenever i run sourcetype=web_ping query in the search bar, splunk PID's increases suddently and it stops the splunk service on HF. Please suggest me where am i going wrong/Help me to fix the issue

We are monitoring around 114 URL's with below sample of inputs.conf

[web_ping://SOMAN]
interval = 2m
title = SOMAN
url = http://sapsoman.www.com:5030/startPage
user_agent = Splunk Website Monitoring (+https://splunkbase.splunk.com/app/1493/)
configuration = default

website_monitoring.conf

[default]
max_response_body_length = 1000
proxy_port = 312
proxy_server = proxy.conexus.svc.local
proxy_type = http
thread_limit = 100

Error:

ERROR [618cf90fac7eff7b2b1290] config:146 - [HTTP 401] Client is not authenticated
Traceback (most recent call last):
File "/opt/app/splunk/splunk/lib/python3.7/site-packages/splunk/appserver/mrsparkle/lib/config.py", line 144, in getServerZoneInfoNoMem
return times.getServerZoneinfo()
File "/opt/app/splunk/splunk/lib/python3.7/site-packages/splunk/appserver/mrsparkle/lib/times.py", line 163, in getServerZoneinfo
serverStatus, serverResp = splunk.rest.simpleRequest('/search/timeparser/tz', sessionKey=sessionKey)
File "/opt/app/splunk/splunk/lib/python3.7/site-packages/splunk/rest/__init__.py", line 553, in simpleRequest
raise splunk.AuthenticationFailed
splunk.AuthenticationFailed: [HTTP 401] Client is not authenticated

 

@LukeMurphey @Anonymous 

Labels (2)
Tags (4)
0 Karma

Ashwini008
Builder

Any help on this please 😕

0 Karma

PickleRick
SplunkTrust
SplunkTrust

I don't know this app but the logs clearly say that you're trying to push HTTP request with no/wrong authentication.

0 Karma

keithevanscdcr
Explorer

Does anyone know how to determine the App/TA that is calling this?

 I had the Zscaler App and TA installed on my test instance and it was throwing an incredible # of errors.  I uninstalled both (zscalersplunkapp, TA-Zscaler_CIM) an these errors disappeared, but I'd like to know how to trace this to the caller instead of removing apps one by one.

TIA!

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Are you sure it's a follow-up to the original post?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

🍂 Fall into November with a fresh lineup of Community Office Hours, Tech Talks, and Webinars we’ve ...

Transform your security operations with Splunk Enterprise Security

Hi Splunk Community, Splunk Platform has set a great foundation for your security operations. With the ...

Splunk Admins and App Developers | Earn a $35 gift card!

Splunk, in collaboration with ESG (Enterprise Strategy Group) by TechTarget, is excited to announce a ...