Splunk Observability Cloud

Trying to use the Splunk OTEL collector on Linux, TOKEN is not working

jeffa2
Explorer

I'm trying to follow these instructions:
https://github.com/signalfx/splunk-otel-collector/blob/main/docs/getting-started/linux-installer.md

...I set up a Splunk trial, and have copied a new token that I created with all read accesses.  I am using the UI here:

app.us1.signalfx.com

When I use the token from the UI that I got from General Settings -> Access Tokens to perform an action with the script I downloaded from the instructions, I get an error.  I run this:

sh splunk-otel-collector.sh --realm us1

Here are the results:

$ sh splunk-otel-collector.sh --realm us1
Please enter your Splunk access token: BHwgwl0s32kbI227gUzORw
Splunk OpenTelemetry Collector Version: latest
Memory Size in MIB: 512
Realm: us1
Ingest Endpoint: https://ingest.us1.signalfx.com
API Endpoint: https://api.us1.signalfx.com
Trace Endpoint: https://ingest.us1.signalfx.com/v2/trace
HEC Endpoint: https://ingest.us1.signalfx.com/v1/log
TD Agent (Fluentd) Version: 4.3.2

Your access token could not be verified. This may be due to a network connectivity issue or an invalid access token.

.......any idea what could be going wrong??

Thank you!!
Jeff

 

Labels (1)
0 Karma
1 Solution

bishida
Splunk Employee
Splunk Employee

Nice! Yes, I meant "ingest" but wrote "access", but you still figured it out 😉

View solution in original post

jeffa2
Explorer

I'm using an access token...  I get it from the UI at General Settings -> Access Tokens.  Here's a screenshot:

access_token.png

0 Karma

jeffa2
Explorer

oh wait, I think I see what you're saying!  I changed to ingest token and it's working now... thank you!!!

0 Karma

bishida
Splunk Employee
Splunk Employee

Nice! Yes, I meant "ingest" but wrote "access", but you still figured it out 😉

bishida
Splunk Employee
Splunk Employee

Oh, by the way--please be sure to make yourself a new token and delete the old ones since the ones you were experimenting with got posted publicly here. Anyone could mess with your instance. 

jeffa2
Explorer

I revoked right after posting 😉  thank you for the help with this!!

0 Karma

bishida
Splunk Employee
Splunk Employee

Hi,

Did you perhaps create and try to use an API token? If so, try using an access token. 

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 2 releases of new security content via the ...

Announcing the 1st Round Champion’s Tribute Winners of the Great Resilience Quest

We are happy to announce the 20 lucky questers who are selected to be the first round of Champion's Tribute ...

We’ve Got Education Validation!

Are you feeling it? All the career-boosting benefits of up-skilling with Splunk? It’s not just a feeling, it's ...