All Apps and Add-ons

Why are there many python error messages from "Prisma Cloud Compute (Twistlock) App for Splunk"?

nareerat_pr
Explorer

Hi, Everyone

I try to collect log with "Prisma Cloud Compute (Twistlock) App for Splunk" (Prisma Cloud Compute (Twistlock) App for Splunk | Splunkbase)

but I found many error messages from the python script follow as the picture below

2022-05-25_17-30-37.png

and this is my inputs.conf

2022-05-25_17-32-50.png

Does anyone have any suggestions?

 

Thank you

Tags (2)
0 Karma

sitthiporns
Explorer

More Information

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py" UnboundLocalError: local variable 'conf_values' referenced before assignment

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"     "console_addr": conf_values["console_addr"],

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"   File "/data1/splunk/etc/apps/twistlock/bin/utils/splunk_sdk.py", line 44, in get_config_stanza

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"     stanza = get_config_stanza(credential["realm"], session_key)

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"   File "/data1/splunk/etc/apps/twistlock/bin/utils/splunk_sdk.py", line 60, in generate_configs

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"     configs = generate_configs(session_key)

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"   File "/data1/splunk/etc/apps/twistlock/bin/poll_incidents.py", line 198, in main

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"     main()

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"   File "/data1/splunk/etc/apps/twistlock/bin/poll_incidents.py", line 233, in <module>

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py" Traceback (most recent call last):

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py" Failed getting configuration from Splunk: ResourceNotFound('https://127.0.0.1:8089/servicesNS/nobody/twistlock/configs/conf-twistlock/None')

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py" Prisma Cloud Compute poll_incidents script started.

setting reschedule_ms=300140, for command=/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_forensics.py" Prisma Cloud Compute poll_forensics script ending.

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_forensics.py" WARNING Incidents file not found.

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_forensics.py" Prisma Cloud Compute poll_forensics script started.

setting reschedule_ms=300174, for command=/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_forensics.py

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py" UnboundLocalError: local variable 'conf_values' referenced before assignment

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"     "console_addr": conf_values["console_addr"],

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"   File "/data1/splunk/etc/apps/twistlock/bin/utils/splunk_sdk.py", line 44, in get_config_stanza

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"     stanza = get_config_stanza(credential["realm"], session_key)

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"   File "/data1/splunk/etc/apps/twistlock/bin/utils/splunk_sdk.py", line 60, in generate_configs

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"     configs = generate_configs(session_key)

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"   File "/data1/splunk/etc/apps/twistlock/bin/poll_incidents.py", line 198, in main

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"     main()

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"   File "/data1/splunk/etc/apps/twistlock/bin/poll_incidents.py", line 233, in <module>

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py" Traceback (most recent call last):

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py" Failed getting configuration from Splunk: ResourceNotFound('https://127.0.0.1:8089/servicesNS/nobody/twistlock/configs/conf-twistlock/None')

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py" Prisma Cloud Compute poll_incidents script started.

setting reschedule_ms=299996, for command=/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_forensics.py" Prisma Cloud Compute poll_forensics script ending.

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_forensics.py" WARNING Incidents file not found.

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_forensics.py" Prisma Cloud Compute poll_forensics script started.

setting reschedule_ms=300002, for command=/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_forensics.py

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py" UnboundLocalError: local variable 'conf_values' referenced before assignment

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"     "console_addr": conf_values["console_addr"],

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"   File "/data1/splunk/etc/apps/twistlock/bin/utils/splunk_sdk.py", line 44, in get_config_stanza

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"     stanza = get_config_stanza(credential["realm"], session_key)

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"   File "/data1/splunk/etc/apps/twistlock/bin/utils/splunk_sdk.py", line 60, in generate_configs

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"     configs = generate_configs(session_key)

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"   File "/data1/splunk/etc/apps/twistlock/bin/poll_incidents.py", line 198, in main

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"     main()

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"   File "/data1/splunk/etc/apps/twistlock/bin/poll_incidents.py", line 233, in <module>

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py" Traceback (most recent call last):

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py" Failed getting configuration from Splunk: ResourceNotFound('https://127.0.0.1:8089/servicesNS/nobody/twistlock/configs/conf-twistlock/None')

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py" Prisma Cloud Compute poll_incidents script started.

setting reschedule_ms=300000, for command=/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_forensics.py" Prisma Cloud Compute poll_forensics script ending.

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_forensics.py" WARNING Incidents file not found.

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_forensics.py" Prisma Cloud Compute poll_forensics script started.

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py" UnboundLocalError: local variable 'conf_values' referenced before assignment

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"     "console_addr": conf_values["console_addr"],

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"   File "/data1/splunk/etc/apps/twistlock/bin/utils/splunk_sdk.py", line 44, in get_config_stanza

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"     stanza = get_config_stanza(credential["realm"], session_key)

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"   File "/data1/splunk/etc/apps/twistlock/bin/utils/splunk_sdk.py", line 60, in generate_configs

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"     configs = generate_configs(session_key)

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"   File "/data1/splunk/etc/apps/twistlock/bin/poll_incidents.py", line 198, in main

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"     main()

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"   File "/data1/splunk/etc/apps/twistlock/bin/poll_incidents.py", line 233, in <module>

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py" Traceback (most recent call last):

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py" Failed getting configuration from Splunk: ResourceNotFound('https://127.0.0.1:8089/servicesNS/nobody/twistlock/configs/conf-twistlock/None')

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py" Prisma Cloud Compute poll_incidents script started.

setting reschedule_ms=299995, for command=/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_forensics.py" Prisma Cloud Compute poll_forensics script ending.

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_forensics.py" WARNING Incidents file not found.

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_forensics.py" Prisma Cloud Compute poll_forensics script started.

setting reschedule_ms=299998, for command=/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_forensics.py

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py" UnboundLocalError: local variable 'conf_values' referenced before assignment

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"     "console_addr": conf_values["console_addr"],

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"   File "/data1/splunk/etc/apps/twistlock/bin/utils/splunk_sdk.py", line 44, in get_config_stanza

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"     stanza = get_config_stanza(credential["realm"], session_key)

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"   File "/data1/splunk/etc/apps/twistlock/bin/utils/splunk_sdk.py", line 60, in generate_configs

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"     configs = generate_configs(session_key)

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"   File "/data1/splunk/etc/apps/twistlock/bin/poll_incidents.py", line 198, in main

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"     main()

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py"   File "/data1/splunk/etc/apps/twistlock/bin/poll_incidents.py", line 233, in <module>

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py" Traceback (most recent call last):

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py" Failed getting configuration from Splunk: ResourceNotFound('https://127.0.0.1:8089/servicesNS/nobody/twistlock/configs/conf-twistlock/None')

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py" Prisma Cloud Compute poll_incidents script started.

setting reschedule_ms=299999, for command=/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_forensics.py" Prisma Cloud Compute poll_forensics script ending.

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_forensics.py" WARNING Incidents file not found.

message from "/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_forensics.py" Prisma Cloud Compute poll_forensics script started.

setting reschedule_ms=299999, for command=/data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_forensics.py

New scheduled exec process: /data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_incidents.py

New scheduled exec process: /data1/splunk/bin/python3.7 /data1/splunk/etc/apps/twistlock/bin/poll_forensics.py

0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...