Hello.I need your help.I installed the Add-on on the internal network LBF and linked it with Azure.Event Hub data is being collected, but Azure Metric data fails to connect.
The error that I got from the log file is
2020-10-19 17:39:59,986 ERROR pid=23114 tid=MainThread file=base_modinput.py:log_error:307 | Get error when collecting events. Traceback (most recent call last):
File "/spldata/splunk/etc/apps/TA-MS-AAD/bin/ta_ms_aad/modinput_wrapper/base_modinput.py", line 127, in stream_events self.collect_events(ew)
File "/spldata/splunk/etc/apps/TA-MS-AAD/bin/azure_metrics.py", line 96, in collect_events input_module.collect_events(self, ew)
File "/spldata/splunk/etc/apps/TA-MS-AAD/bin/input_module_azure_metrics.py", line 44, in collect_events access_token = azauth.get_mgmt_access_token(client_id, client_secret, tenant_id, environment, helper)
File "/spldata/splunk/etc/apps/TA-MS-AAD/bin/ta_azure_utils/auth.py", line 53, in get_mgmt_access_token raise e ConnectionError: HTTPSConnectionPool(host='login.microsoftonline.com', port=443): Max retries exceeded with url: /8db7ee9a-5c88/oauth2/token (Caused by NewConnectionError('<requests.packages.urllib3.connection.VerifiedHTTPSConnection object at 0x7f59df>: Failed to establish a new connection: [Errno 110] Connection timed out',))
splunk Enterprise version : 7.2.6
python version : 2.6
add-on : Microsoft Azure Add on for Splunk
There were no problems in testing on my personal laptop.Can anyone provide me the cause and response?
I believe connection is directly hitting firewall where your source IP is not allowed to make connection. if you have proxy in your company to connect internet then you must use proxy details in TA configuration.