All Apps and Add-ons

Why am I getting this error Issue with Microsoft Azure add-on for Splunk?

jwalzerpitt
Influencer

I have been using Microsoft Azure add-on for Splunk to ingest Azure sign in logs for over a year and today I see the following error:

 

 

021-11-08 16:31:12,318 ERROR pid=4614 tid=MainThread file=base_modinput.py:log_error:309 | Traceback (most recent call last):

File "/opt/splunk/etc/apps/TA-MS-AAD/bin/ta_ms_aad/aob_py3/splunklib/binding.py", line 1262, in request
    raise HTTPError(response)
splunklib.binding.HTTPError: HTTP 500 Internal Server Error -- b'{"messages":[{"type":"ERROR","text":"Unexpected error \\"<class \'splunktaucclib.rest_handler.error.RestError\'>\\" from python handler: \\"REST Error [400]: Bad Request -- HTTP 400 Bad Request -- int() argument must be a string, a bytes-like object or a number, not \'NoneType\'\\".  See splunkd.log for more details."}]}'

 

 

 

Has anyone else experiencing this issue?

Labels (1)
Tags (3)
0 Karma

wstarowicz
Path Finder

I managed to fix it. I edited credentials in addon configuration and saved it. The same for inputs - edit & save. Started to work.

jwalzerpitt
Influencer

I recreated the input on the add-on and recreated the app registration in Azure and still not working for me

0 Karma

SinghK
Builder

All these addons write to specific logfile can you search for more specific error in there. Mostly these addons have webhooks that they use to get data from azure application and if this one is also using a webhook is that webhook publicly available. and when the data is fetched it writes to a check point file somewhere and that gets corrupt too. 

0 Karma

wstarowicz
Path Finder

Same for me...

 

2021-11-09 09:34:44,317 ERROR pid=8468 tid=MainThread file=base_modinput.py:log_error:309 | _Splunk_ Unable to obtain access token

0 Karma

gaurav_maniar
Builder

Hi,

Have you guys found any fix for this issue??

Thanks.

0 Karma

yamamotokentis
Observer

Hi,

I have been using Microsoft Azure add-on for Splunk for a year.
I also saw following message,

"ERROR pid=9511 tid=MainThread file=base_modinput.py:log_error:309 | _Splunk_ Unable to obtain access token"

And create new secret id and value on Azure AD, and apply it ot the splunk app.
However I could not fix the issue.

Has anyone else experiencing this issue?

 

 

0 Karma

pagillar
Explorer

was this issue fixed?

0 Karma

yamamotokentis
Observer

Yes, fixed.  However the cause is unknown.. 

0 Karma

pagillar
Explorer

what did you do to fix the issue? 

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...