I am trying to use Splunk Add-on for Office 365 on a HWF.

I have found one other question relating to "Resource temporarily unavailable" but the solution is not applicable.

It is collecting most events and they are visible in search, however no SharePoint audit events are showing. Splunkd.log shows the following errors for the TA:

message from "python /opt/splunk/etc/apps/splunk_ta_o365/bin/"

IOError: [Errno 11] Resource temporarily unavailable
        fcntl.flock(fd, fcntl.LOCK_EX | fcntl.LOCK_NB)
    File "/opt/splunk/etc/apps/splunk_ta_o365/bin/splunksdc/", line 22, in lock
    File "/opt/splunk/etc/apps/splunk_ta_o365/bin/splunksdc/", line 42, in acquire
    File "/opt/splunk/etc/apps/splunk_ta_o365/bin/splunksdc/", line 48, in __enter__
        with self._sylock(folder):
    File "/opt/splunk/etc/apps/splunk_ta_o365/bin/splunksdc/", line 244, in run
        code =
    File "/opt/splunk/etc/apps/splunk_ta_o365/bin/splunksdc/", line 118, in run_modular_input
        run_modular_input(factory, **kwargs)
    File "/opt/splunk/etc/apps/splunk_ta_o365/bin/splunksdc/", line 199, in main
    File "/opt/splunk/etc/apps/splunk_ta_o365/bin/splunk_ta_o365/modinputs/", line 216, in main
    File "/opt/splunk/etc/apps/splunk_ta_o365/bin/", line 34, in run_module
    File "/opt/splunk/etc/apps/splunk_ta_o365/bin/", line 4, in <module>
Traceback (most recent call last):   

Any help appreciated,

