Archive
Highlighted

Error during Splunk Business Flow configuration

New Member

I am trying to configure the trial of Splunk Business Flow on Splunk Enterprise (a trial) on Windows.
I checked to have respected all requirements following the documentation, and all deployment check results in the app are ok.

Otherwise, when I try to complete the registration, I receive this error:
Error processing registration: register error during encryption/decryption. X-Request-ID: e3f95c26-1112-442a-bec1-7032e4b1b85f.

In the log error, I find this:
** [SplunkClient] ERROR requestID:8c79e81a-473e-4b83-a480-09b4a5be9bd3 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud_public.pem**

Indeed there is not that pem file in that directory.
I tried from installing Business Flow app from the App section in Splunk and from file both.

If someone could help me, I would be really thankful!

0 Karma
Highlighted

Re: Error during Splunk Business Flow configuration

Splunk Employee
Splunk Employee

Hi! Please upload your logs so the team can review and troubleshoot. If you are receiving an error, there should be a link to "Send report to Splunk" or something like that. You can also upload logs by changing the end of your url "app/splunk-business-flow/home" to "app/splunk-business-flow/diag"

0 Karma
Highlighted

Re: Error during Splunk Business Flow configuration

New Member

Hi!
I cannot upload a file here because I do not have karma points enough. I copy here part of the log, from the beginning.
Thank you

2020-02-25 10:34:14,274 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2CACERTS): None
2020-02-25 10:34:14,345 [SplunkClient] INFO requestID:4349b403-4c94-4bc5-9600-c39a62d93235 PEM password not found, generating new password.
2020-02-25 10:34:14,777 [SplunkClient] INFO requestID:4349b403-4c94-4bc5-9600-c39a62d93235 Storing new PEM password.
2020-02-25 10:34:14,797 [SplunkClient] INFO requestID:4349b403-4c94-4bc5-9600-c39a62d93235 Successfully stored new PEM password.
2020-02-25 10:34:14,798 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2CACERTS): None
2020-02-25 10:34:14,818 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 10:34:15,649 [SplunkClient] INFO requestID:4349b403-4c94-4bc5-9600-c39a62d93235 PEM file not found in KV store, read PEM file locally
2020-02-25 10:34:15,656 [SplunkClient] INFO requestID:4349b403-4c94-4bc5-9600-c39a62d93235 Store PEM file in KV store
2020-02-25 10:34:15,703 [SplunkClient] INFO requestID:4349b403-4c94-4bc5-9600-c39a62d93235 PEM file not found in KV store, read PEM file locally
2020-02-25 10:34:15,710 [SplunkClient] INFO requestID:4349b403-4c94-4bc5-9600-c39a62d93235 Store PEM file in KV store
2020-02-25 10:34:15,735 [SplunkClient] INFO requestID:4349b403-4c94-4bc5-9600-c39a62d93235 PEM file not found in KV store, read PEM file locally
2020-02-25 10:34:15,742 [SplunkClient] ERROR requestID:4349b403-4c94-4bc5-9600-c39a62d93235 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloudpublic.pem
2020-02-25 10:34:15,742 [SBFRestManager] INFO requestID:4349b403-4c94-4bc5-9600-c39a62d93235 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud
public.pem
2020-02-25 10:34:15,742 [SBFRestManager] INFO requestID:4349b403-4c94-4bc5-9600-c39a62d93235 Requesting "/init" endpoint
2020-02-25 10:34:15,993 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2CACERTS): None
2020-02-25 10:34:16,055 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2CACERTS): None
2020-02-25 10:34:16,079 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 10:34:16,143 [SplunkClient] INFO requestID:8c79e81a-473e-4b83-a480-09b4a5be9bd3 PEM file not found in KV store, read PEM file locally
2020-02-25 10:34:16,148 [SplunkClient] ERROR requestID:8c79e81a-473e-4b83-a480-09b4a5be9bd3 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloudpublic.pem
2020-02-25 10:34:16,148 [SBFRestManager] INFO requestID:8c79e81a-473e-4b83-a480-09b4a5be9bd3 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud
public.pem
2020-02-25 10:34:16,148 [SBFRestManager] INFO requestID:8c79e81a-473e-4b83-a480-09b4a5be9bd3 Requesting "/registerpayload" endpoint
2020-02-25 10:34:18,818 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2
CACERTS): None
2020-02-25 10:34:18,865 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2
CACERTS): None
2020-02-25 10:34:18,888 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 10:34:18,949 [SplunkClient] INFO requestID:65b7d256-3b42-4e58-aec2-971c3621e0cc PEM file not found in KV store, read PEM file locally
2020-02-25 10:34:18,965 [SplunkClient] ERROR requestID:65b7d256-3b42-4e58-aec2-971c3621e0cc Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud
public.pem
2020-02-25 10:34:18,965 [SBFRestManager] INFO requestID:65b7d256-3b42-4e58-aec2-971c3621e0cc Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloudpublic.pem
2020-02-25 10:34:18,965 [SBFRestManager] INFO requestID:65b7d256-3b42-4e58-aec2-971c3621e0cc Requesting "/deployment
check" endpoint
2020-02-25 10:34:18,966 [DeploymentCheck] INFO requestID:65b7d256-3b42-4e58-aec2-971c3621e0cc Starting deployment check
2020-02-25 10:34:23,032 [DeploymentCheck] INFO requestID:65b7d256-3b42-4e58-aec2-971c3621e0cc {
"nodeName": "T470-PF0Y56UA",
"results": [
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://us.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 09:34:17 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://us.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://eu.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 09:34:18 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://eu.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://apac.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 09:34:20 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://apac.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {},
"isError": false,
"testName": "Testing app install folder permissions"
}
]
}
2020-02-25 14:02:48,443 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2CACERTS): None
2020-02-25 14:02:48,524 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2CACERTS): None
2020-02-25 14:02:48,551 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 14:02:48,604 [SplunkClient] INFO requestID:cfbe699f-388b-4b61-bd11-345be6f899d2 PEM file not found in KV store, read PEM file locally
2020-02-25 14:02:48,611 [SplunkClient] ERROR requestID:cfbe699f-388b-4b61-bd11-345be6f899d2 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloudpublic.pem
2020-02-25 14:02:48,611 [SBFRestManager] INFO requestID:cfbe699f-388b-4b61-bd11-345be6f899d2 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud
public.pem
2020-02-25 14:02:48,611 [SBFRestManager] INFO requestID:cfbe699f-388b-4b61-bd11-345be6f899d2 Requesting "/init" endpoint
2020-02-25 14:02:49,219 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2CACERTS): None
2020-02-25 14:02:49,296 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2CACERTS): None
2020-02-25 14:02:49,315 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 14:02:49,350 [SplunkClient] INFO requestID:b0355b8c-c958-40d1-a8d3-4aafde530940 PEM file not found in KV store, read PEM file locally
2020-02-25 14:02:49,355 [SplunkClient] ERROR requestID:b0355b8c-c958-40d1-a8d3-4aafde530940 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloudpublic.pem
2020-02-25 14:02:49,356 [SBFRestManager] INFO requestID:b0355b8c-c958-40d1-a8d3-4aafde530940 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud
public.pem
2020-02-25 14:02:49,356 [SBFRestManager] INFO requestID:b0355b8c-c958-40d1-a8d3-4aafde530940 Requesting "/registerpayload" endpoint
2020-02-25 14:02:52,029 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2
CACERTS): None
2020-02-25 14:02:52,069 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2
CACERTS): None
2020-02-25 14:02:52,082 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 14:02:52,117 [SplunkClient] INFO requestID:73926389-4a50-485c-b850-1b0db86425b0 PEM file not found in KV store, read PEM file locally
2020-02-25 14:02:52,122 [SplunkClient] ERROR requestID:73926389-4a50-485c-b850-1b0db86425b0 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud
public.pem
2020-02-25 14:02:52,122 [SBFRestManager] INFO requestID:73926389-4a50-485c-b850-1b0db86425b0 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloudpublic.pem
2020-02-25 14:02:52,122 [SBFRestManager] INFO requestID:73926389-4a50-485c-b850-1b0db86425b0 Requesting "/deployment
check" endpoint
2020-02-25 14:02:52,123 [DeploymentCheck] INFO requestID:73926389-4a50-485c-b850-1b0db86425b0 Starting deployment check
2020-02-25 14:02:55,867 [DeploymentCheck] INFO requestID:73926389-4a50-485c-b850-1b0db86425b0 {
"nodeName": "T470-PF0Y56UA",
"results": [
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://us.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 13:02:51 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://us.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://eu.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 13:02:51 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://eu.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://apac.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 13:02:53 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://apac.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {},
"isError": false,
"testName": "Testing app install folder permissions"
}
]
}
2020-02-25 15:28:08,053 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2CACERTS): None
2020-02-25 15:28:08,154 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2CACERTS): None
2020-02-25 15:28:08,171 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 15:28:08,260 [SplunkClient] INFO requestID:5b952c5b-bb6c-41b8-9242-d0e65dcfd05b PEM file not found in KV store, read PEM file locally
2020-02-25 15:28:08,272 [SplunkClient] ERROR requestID:5b952c5b-bb6c-41b8-9242-d0e65dcfd05b Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloudpublic.pem
2020-02-25 15:28:08,272 [SBFRestManager] INFO requestID:5b952c5b-bb6c-41b8-9242-d0e65dcfd05b Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud
public.pem
2020-02-25 15:28:08,273 [SBFRestManager] INFO requestID:5b952c5b-bb6c-41b8-9242-d0e65dcfd05b Requesting "/init" endpoint
2020-02-25 15:28:08,637 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2CACERTS): None
2020-02-25 15:28:08,723 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2CACERTS): None
2020-02-25 15:28:08,746 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 15:28:08,797 [SplunkClient] INFO requestID:f2f5070d-d764-4b03-b097-3a1afdf135b6 PEM file not found in KV store, read PEM file locally
2020-02-25 15:28:08,802 [SplunkClient] ERROR requestID:f2f5070d-d764-4b03-b097-3a1afdf135b6 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloudpublic.pem
2020-02-25 15:28:08,802 [SBFRestManager] INFO requestID:f2f5070d-d764-4b03-b097-3a1afdf135b6 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud
public.pem
2020-02-25 15:28:08,802 [SBFRestManager] INFO requestID:f2f5070d-d764-4b03-b097-3a1afdf135b6 Requesting "/registerpayload" endpoint
2020-02-25 15:28:12,550 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2
CACERTS): None
2020-02-25 15:28:12,626 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2
CACERTS): None
2020-02-25 15:28:12,648 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 15:28:12,742 [SplunkClient] INFO requestID:c3cd32c5-9aea-46b2-97ea-d394ff3ca1d5 PEM file not found in KV store, read PEM file locally
2020-02-25 15:28:12,764 [SplunkClient] ERROR requestID:c3cd32c5-9aea-46b2-97ea-d394ff3ca1d5 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud
public.pem
2020-02-25 15:28:12,764 [SBFRestManager] INFO requestID:c3cd32c5-9aea-46b2-97ea-d394ff3ca1d5 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloudpublic.pem
2020-02-25 15:28:12,764 [SBFRestManager] INFO requestID:c3cd32c5-9aea-46b2-97ea-d394ff3ca1d5 Requesting "/deployment
check" endpoint
2020-02-25 15:28:12,766 [DeploymentCheck] INFO requestID:c3cd32c5-9aea-46b2-97ea-d394ff3ca1d5 Starting deployment check
2020-02-25 15:28:16,265 [DeploymentCheck] INFO requestID:c3cd32c5-9aea-46b2-97ea-d394ff3ca1d5 {
"nodeName": "T470-PF0Y56UA",
"results": [
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://us.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 14:28:11 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://us.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://eu.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 14:28:12 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://eu.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://apac.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 14:28:14 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://apac.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {},
"isError": false,
"testName": "Testing app install folder permissions"
}
]
}
2020-02-25 15:29:45,773 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2CACERTS): None
2020-02-25 15:29:45,903 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2CACERTS): None
2020-02-25 15:29:45,927 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 15:29:45,978 [SplunkClient] INFO requestID:ec0b1c14-df21-4606-8efb-bb9014a78b1e PEM file not found in KV store, read PEM file locally
2020-02-25 15:29:45,985 [SplunkClient] ERROR requestID:ec0b1c14-df21-4606-8efb-bb9014a78b1e Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloudpublic.pem
2020-02-25 15:29:45,986 [SBFRestManager] INFO requestID:ec0b1c14-df21-4606-8efb-bb9014a78b1e Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud
public.pem
2020-02-25 15:29:45,986 [SBFRestManager] INFO requestID:ec0b1c14-df21-4606-8efb-bb9014a78b1e Requesting "/init" endpoint
2020-02-25 15:29:46,372 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2CACERTS): None
2020-02-25 15:29:46,425 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2CACERTS): None
2020-02-25 15:29:46,439 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 15:29:46,543 [SplunkClient] INFO requestID:605a4e97-579c-49ed-8755-b8738383b8cb PEM file not found in KV store, read PEM file locally
2020-02-25 15:29:46,554 [SplunkClient] ERROR requestID:605a4e97-579c-49ed-8755-b8738383b8cb Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloudpublic.pem
2020-02-25 15:29:46,554 [SBFRestManager] INFO requestID:605a4e97-579c-49ed-8755-b8738383b8cb Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud
public.pem
2020-02-25 15:29:46,556 [SBFRestManager] INFO requestID:605a4e97-579c-49ed-8755-b8738383b8cb Requesting "/registerpayload" endpoint
2020-02-25 15:29:49,604 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2
CACERTS): None
2020-02-25 15:29:49,690 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2
CACERTS): None
2020-02-25 15:29:49,729 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 15:29:49,808 [SplunkClient] INFO requestID:2b8c5525-586b-417a-bb47-478249fc18db PEM file not found in KV store, read PEM file locally
2020-02-25 15:29:49,816 [SplunkClient] ERROR requestID:2b8c5525-586b-417a-bb47-478249fc18db Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud
public.pem
2020-02-25 15:29:49,816 [SBFRestManager] INFO requestID:2b8c5525-586b-417a-bb47-478249fc18db Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloudpublic.pem
2020-02-25 15:29:49,816 [SBFRestManager] INFO requestID:2b8c5525-586b-417a-bb47-478249fc18db Requesting "/deployment
check" endpoint
2020-02-25 15:29:49,818 [DeploymentCheck] INFO requestID:2b8c5525-586b-417a-bb47-478249fc18db Starting deployment check
2020-02-25 15:29:54,284 [DeploymentCheck] INFO requestID:2b8c5525-586b-417a-bb47-478249fc18db {
"nodeName": "T470-PF0Y56UA",
"results": [
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://us.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 14:29:48 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://us.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://eu.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 14:29:49 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://eu.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://apac.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 14:29:52 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://apac.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {},
"isError": false,
"testName": "Testing app install folder permissions"
}
]
}
2020-02-25 15:30:13,718 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2CACERTS): None
2020-02-25 15:30:13,827 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2CACERTS): None
2020-02-25 15:30:13,851 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 15:30:13,924 [SplunkClient] INFO requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e PEM file not found in KV store, read PEM file locally
2020-02-25 15:30:13,936 [SplunkClient] ERROR requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloudpublic.pem
2020-02-25 15:30:13,936 [SBFRestManager] INFO requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud
public.pem
2020-02-25 15:30:13,936 [SBFRestManager] INFO requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Requesting "/register" endpoint
2020-02-25 15:30:13,964 [RegisterCommand] INFO requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Collecting info needed for registration
2020-02-25 15:30:13,997 [SplunkClient] DEBUG requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Connecting to: https://127.0.0.1:8089/servicesNS/nobody/splunk-business-flow/properties/sbf/server/url_eu
2020-02-25 15:30:14,005 [SplunkClient] DEBUG requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Connecting to: https://127.0.0.1:8089/servicesNS/nobody/splunk-business-flow/properties/sbf/server
2020-02-25 15:30:14,019 [SplunkClient] ERROR requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Failed to execute: https://127.0.0.1:8089/servicesNS/nobody/splunk-business-flow/properties/sbf/server Err: Expecting value: line 1 column 1 (char 0)
Traceback (most recent call last):
File "C:\Program Files\Splunk\etc\apps\splunk-business-flow\bin\splunkdclient.py", line 187, in _getconfigurl
results[configname]=json.loads(data)
File "C:\Program Files\Splunk\Python-3.7\lib\json_
init.py", line 348, in loads
return defaultdecoder.decode(s)
File "C:\Program Files\Splunk\Python-3.7\lib\json\decoder.py", line 337, in decode
obj, end = self.rawdecode(s, idx=w(s, 0).end())
File "C:\Program Files\Splunk\Python-3.7\lib\json\decoder.py", line 355, in rawdecode
raise JSONDecodeError("Expecting value", s, err.value) from None
json.decoder.JSONDecodeError: Expecting value: line 1 column 1 (char 0)
2020-02-25 15:30:14,022 [SplunkClient] DEBUG requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Connecting to: https://127.0.0.1:8089/servicesNS/nobody/splunk-business-flow/properties/cloud/server
2020-02-25 15:30:14,038 [SplunkClient] ERROR requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Failed to execute: https://127.0.0.1:8089/servicesNS/nobody/splunk-business-flow/properties/cloud/server Err: Expecting value: line 1 column 1 (char 0)
Traceback (most recent call last):
File "C:\Program Files\Splunk\etc\apps\splunk-business-flow\bin\splunkd
client.py", line 187, in _getconfigurl
results[config
name]=json.loads(data)
File "C:\Program Files\Splunk\Python-3.7\lib\json__init
.py", line 348, in loads
return defaultdecoder.decode(s)
File "C:\Program Files\Splunk\Python-3.7\lib\json\decoder.py", line 337, in decode
obj, end = self.rawdecode(s, idx=w(s, 0).end())
File "C:\Program Files\Splunk\Python-3.7\lib\json\decoder.py", line 355, in rawdecode
raise JSONDecodeError("Expecting value", s, err.value) from None
json.decoder.JSONDecodeError: Expecting value: line 1 column 1 (char 0)
2020-02-25 15:30:14,039 [SplunkClient] DEBUG requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Connecting to: https://127.0.0.1:8089/servicesNS/nobody/splunk-business-flow/properties/sbf/server/url
prod
2020-02-25 15:30:14,048 [RegisterCommand] INFO requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Checking cloud server health
2020-02-25 15:30:14,049 [SplunkClient] DEBUG requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Connecting to: https://127.0.0.1:8089/servicesNS/nobody/splunk-business-flow/properties/sbf/server/url_prod
2020-02-25 15:30:14,057 [CloudHealthCommand] INFO requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e cloud server is https://eu.businessflowapp.splunk.com
2020-02-25 15:30:14,183 [RegisterCommand] INFO requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Cloud server health OK: https://eu.businessflowapp.splunk.com
2020-02-25 15:30:14,184 [RegisterCommand] INFO requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Cloud Server for registration: https://eu.businessflowapp.splunk.com
2020-02-25 15:30:14,184 [RegisterCommand] INFO requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Starting read of public key
2020-02-25 15:30:14,195 [RegisterCommand] INFO requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e Read public key
2020-02-25 15:30:15,384 [Encryption] INFO Error with unlink: C:\WINDOWS\TEMP\tmprbr6mxl
2020-02-25 15:30:15,385 [Encryption] INFO Error with unlink: C:\WINDOWS\TEMP\tmprb
r6mxl
2020-02-25 15:30:15,385 [SBFRestManager] ERROR requestID:60a7dcc9-4c24-43fd-b65c-26dae406899e ('register error during encryption/decryption', EncryptionException('Error with decrypt', TypeError("a bytes-like object is required, not 'str'")))
Traceback (most recent call last):
File "C:\Program Files\Splunk\etc\apps\splunk-business-flow\bin\encryption.py", line 156, in decrypt
opensslstatus=self.callopenssl(['aes-256-cbc','-d','-salt','-K',key,'-iv',initvector,'-in',tempfilein.name,'-out',tempfileout.name])
File "C:\Program Files\Splunk\etc\apps\splunk-business-flow\bin\encryption.py", line 174, in call
openssl
return call(['{}/bin/splunk'.format(self.splunk_home),'cmd','openssl']+args)
File "C:\Program Files\Splunk\Python-3.7\lib\subprocess.py", line 323, in call
with Popen(
popenargs, **kwargs) as p:
File "C:\Program Files\Splunk\Python-3.7\lib\subprocess.py", line 775, in init
restoresignals, startnewsession)
File "C:\Program Files\Splunk\Python-3.7\lib\subprocess.py", line 1119, in _execute
child
args = list2cmdline(args)
File "C:\Program Files\Splunk\Python-3.7\lib\subprocess.py", line 530, in list2cmdline
needquote = (" " in arg) or ("\t" in arg) or not arg
TypeError: a bytes-like object is required, not 'str'

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
File "C:\Program Files\Splunk\etc\apps\splunk-business-flow\bin\registercommand.py", line 80, in _cloudregister
result,content,respdecrypted=self.cloudclient.post(url,body)
File "C:\Program Files\Splunk\etc\apps\splunk-business-flow\bin\cloudclient.py", line 24, in post
decrypted=self.encryption.decrypt(resp['msg'],self.cja
priv,py23decode(resp['key']),self.pempassword)
File "C:\Program Files\Splunk\etc\apps\splunk-business-flow\bin\encryption.py", line 162, in decrypt
raise EncryptionException("Error with decrypt",ex)
encryption.EncryptionException: ('Error with decrypt', TypeError("a bytes-like object is required, not 'str'"))

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
File "C:\Program Files\Splunk\etc\apps\splunk-business-flow\bin\sbfrestmanager.py", line 55, in handle
return RegisterCommand(dependencies).execute()
File "C:\Program Files\Splunk\etc\apps\splunk-business-flow\bin\registercommand.py", line 57, in execute
returned
tenantid,registrationid,warning=self.cloudregister(registerpayload)
File "C:\Program Files\Splunk\etc\apps\splunk-business-flow\bin\register
command.py", line 101, in cloudregister
raise RegisterEndpointException(CJAResponse.STATUSERRORINTERNAL,'register error during encryption/decryption',ex)
registercommand.RegisterEndpointException: ('register error during encryption/decryption', EncryptionException('Error with decrypt', TypeError("a bytes-like object is required, not 'str'")))
2020-02-25 15:30:20,960 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2
CACERTS): None
2020-02-25 15:30:21,024 [HTTPClient] INFO Using root CA certificate file (HTTPLIB2
CACERTS): None
2020-02-25 15:30:21,044 [HTTPClient] INFO Proxy is not enabled.
2020-02-25 15:30:21,124 [SplunkClient] INFO requestID:ebeb1264-e60c-441d-9220-cfad89b0abe6 PEM file not found in KV store, read PEM file locally
2020-02-25 15:30:21,143 [SplunkClient] ERROR requestID:ebeb1264-e60c-441d-9220-cfad89b0abe6 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloud
public.pem
2020-02-25 15:30:21,143 [SBFRestManager] INFO requestID:ebeb1264-e60c-441d-9220-cfad89b0abe6 Error reading file : C:\Program Files\Splunk\etc\apps\splunk-business-flow\local\cloudpublic.pem
2020-02-25 15:30:21,143 [SBFRestManager] INFO requestID:ebeb1264-e60c-441d-9220-cfad89b0abe6 Requesting "/deployment
check" endpoint
2020-02-25 15:30:21,145 [DeploymentCheck] INFO requestID:ebeb1264-e60c-441d-9220-cfad89b0abe6 Starting deployment check
2020-02-25 15:30:23,753 [DeploymentCheck] INFO requestID:ebeb1264-e60c-441d-9220-cfad89b0abe6 {
"nodeName": "T470-PF0Y56UA",
"results": [
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://us.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 14:30:20 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://us.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://eu.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 14:30:20 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://eu.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {
"content-length": "15",
"content-location": "https://apac.businessflowapp.splunk.com/health",
"content-type": "text/plain; charset=utf-8",
"date": "Tue, 25 Feb 2020 14:30:21 GMT",
"status": "200",
"vary": "Origin"
},
"isError": false,
"testName": "Testing Splunk connection to: https://apac.businessflowapp.splunk.com/health"
},
{
"errorMessage": null,
"info": {},
"isError": false,
"testName": "Testing app install folder permissions"
}
]
}*

0 Karma
Highlighted

Re: Error during Splunk Business Flow configuration

Splunk Employee
Splunk Employee

We have identified the issue as being related to Windows 10. We are working on a fix and I will let you know when it's fixed.

0 Karma