Hi all,
We installed latest Microsoft Azure Active Directory Reporting Add-on for Splunk on our installation running 7.0.
We configured inputs for Signing and Audit data. However, there is no data received. Found same error in logs of each input:
2018-05-18 16:29:34,344 ERROR pid=14469 tid=MainThread file=base_modinput.py:log_error:307 | Traceback (most recent call last):
File "/opt/splunk/etc/apps/TA-MS-AAD/bin/ta_ms_aad/modinput_wrapper/base_modinput.py", line 113, in stream_events
self.parse_input_args(input_definition)
File "/opt/splunk/etc/apps/TA-MS-AAD/bin/ta_ms_aad/modinput_wrapper/base_modinput.py", line 152, in parse_input_args
self._parse_input_args_from_global_config(inputs)
File "/opt/splunk/etc/apps/TA-MS-AAD/bin/ta_ms_aad/modinput_wrapper/base_modinput.py", line 170, in _parse_input_args_from_global_config
global_config = GlobalConfig(uri, session_key, global_schema)
File "/opt/splunk/etc/apps/TA-MS-AAD/bin/ta_ms_aad/splunktaucclib/global_config/__init__.py", line 51, in __init__
port=splunkd_info.port,
File "/opt/splunk/etc/apps/TA-MS-AAD/bin/ta_ms_aad/solnlib/net_utils.py", line 129, in wrapper
'Illegal argument: {}={}'.format(arg, value))
ValueError: Illegal argument: host=::1
I wonder if it's caused by the Sign-on URL to https://localhost as mentioned in the link about "prerequisites to access the Azure AD reporting API.", while our system runs IPv4 and IPv6. Seems the v6 localhost address ::1 is invalid.
Would anyone please help?
Thanks a lot.
/ST Wong
... View more