All Apps and Add-ons

Website Monitoring App stops the splunk service

Ashwini008
Builder

Hi All,

I am using Website Monitoring in one of our HF.But whenever i run sourcetype=web_ping query in the search bar, splunk PID's increases suddently and it stops the splunk service on HF. Please suggest me where am i going wrong/Help me to fix the issue

We are monitoring around 114 URL's with below sample of inputs.conf

[web_ping://SOMAN]
interval = 2m
title = SOMAN
url = http://sapsoman.www.com:5030/startPage
user_agent = Splunk Website Monitoring (+https://splunkbase.splunk.com/app/1493/)
configuration = default

website_monitoring.conf

[default]
max_response_body_length = 1000
proxy_port = 312
proxy_server = proxy.conexus.svc.local
proxy_type = http
thread_limit = 100

Error:

ERROR [618cf90fac7eff7b2b1290] config:146 - [HTTP 401] Client is not authenticated
Traceback (most recent call last):
File "/opt/app/splunk/splunk/lib/python3.7/site-packages/splunk/appserver/mrsparkle/lib/config.py", line 144, in getServerZoneInfoNoMem
return times.getServerZoneinfo()
File "/opt/app/splunk/splunk/lib/python3.7/site-packages/splunk/appserver/mrsparkle/lib/times.py", line 163, in getServerZoneinfo
serverStatus, serverResp = splunk.rest.simpleRequest('/search/timeparser/tz', sessionKey=sessionKey)
File "/opt/app/splunk/splunk/lib/python3.7/site-packages/splunk/rest/__init__.py", line 553, in simpleRequest
raise splunk.AuthenticationFailed
splunk.AuthenticationFailed: [HTTP 401] Client is not authenticated

 

@LukeMurphey @Anonymous 

Labels (2)
Tags (4)
0 Karma

Ashwini008
Builder

Any help on this please 😕

0 Karma

PickleRick
SplunkTrust
SplunkTrust

I don't know this app but the logs clearly say that you're trying to push HTTP request with no/wrong authentication.

0 Karma

keithevanscdcr
Explorer

Does anyone know how to determine the App/TA that is calling this?

 I had the Zscaler App and TA installed on my test instance and it was throwing an incredible # of errors.  I uninstalled both (zscalersplunkapp, TA-Zscaler_CIM) an these errors disappeared, but I'd like to know how to trace this to the caller instead of removing apps one by one.

TIA!

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Are you sure it's a follow-up to the original post?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...