Splunk Cloud Platform

Script Error xml.etree.ElementTree.ParseError

PierrAlezOCD
New Member

Hello,

We repeatedly receive this message when collecting information via the plugin:


2025-09-29 08:30:44,656 ERROR pid=1278370 tid=MainThread file=base_modinput.py:log_error:309 | Get error when collecting events.
Traceback (most recent call last):
File "/opt/splunk/etc/apps/BeyondTrust-RS-Integration/bin/beyondtrust_rs_integration/aob_py3/modinput_wrapper/base_modinput.py", line 128, in stream_events
self.collect_events(ew)
File "/opt/splunk/etc/apps/BeyondTrust-RS-Integration/bin/beyondtrust_rs_reporting_api_session_events.py", line 72, in collect_events
input_module.collect_events(self, ew)
File "/opt/splunk/etc/apps/BeyondTrust-RS-Integration/bin/input_module_beyondtrust_rs_reporting_api_session_events.py", line 56, in collect_events
session_tree = ET.fromstring(session_report)
File "/opt/splunk/lib/python3.9/xml/etree/ElementTree.py", line 1348, in XML
return parser.close()
xml.etree.ElementTree.ParseError: no element found: line 2061329, column 21

 

 

Do you have any ideas on how to fix this issue?

Labels (1)
0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @PierrAlezOCD 

It looks like the data is being received from BeyondTrust by the API because its referencing a specific line that is failing the xml function which makes me wonder if something is incorrect or changed in the events received from BeyondTrust which the app cannot handle.

Are you using the latest version of the app from Splunkbase?

You may be able to speak to BeyondTrust directly through your support channels with them as they state in the docs that they do support the Splunk app (https://docs.beyondtrust.com/rs/docs/splunk

🌟 Did this answer help you? If so, please consider:

  • Adding karma to show it was useful
  • Marking it as the solution if it resolved your issue
  • Commenting if you need any clarification

Your feedback encourages the volunteers in this community to continue contributing

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...