IT Operations Discussions
All the up-time. All the nines.

Microsoft Azure Add on for Splunk : in get mgmt access token raise e ConnectionError

imheejin
Explorer

 

Hello.
I need your help.
I installed the Add-on on the internal network LBF and linked it with Azure.
Event Hub data is being collected, but Azure Metric data fails to connect.

The error that I got from the log file is

2020-10-19 17:39:59,986 ERROR pid=23114 tid=MainThread file=base_modinput.py:log_error:307 | Get error when collecting events. Traceback (most recent call last):

File "/spldata/splunk/etc/apps/TA-MS-AAD/bin/ta_ms_aad/modinput_wrapper/base_modinput.py", line 127, in stream_events self.collect_events(ew)

File "/spldata/splunk/etc/apps/TA-MS-AAD/bin/azure_metrics.py", line 96, in collect_events input_module.collect_events(self, ew)

File "/spldata/splunk/etc/apps/TA-MS-AAD/bin/input_module_azure_metrics.py", line 44, in collect_events access_token = azauth.get_mgmt_access_token(client_id, client_secret, tenant_id, environment, helper)

File "/spldata/splunk/etc/apps/TA-MS-AAD/bin/ta_azure_utils/auth.py", line 53, in get_mgmt_access_token raise e ConnectionError: HTTPSConnectionPool(host='login.microsoftonline.com', port=443): Max retries exceeded with url: /8db7ee9a-5c88/oauth2/token (Caused by NewConnectionError('<requests.packages.urllib3.connection.VerifiedHTTPSConnection object at 0x7f59df>: Failed to establish a new connection: [Errno 110] Connection timed out',))

 

splunk Enterprise version : 7.2.6 

python version : 2.6

add-on : Microsoft Azure Add on for Splunk

 

There were no problems in testing on my personal laptop.
Can anyone provide me the cause and response?

Tags (2)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

I believe connection is directly hitting firewall where your source IP is not allowed to make connection. if you have proxy in your company to connect internet then you must use proxy details in TA configuration.

————————————
If this helps, give a like below.
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...