Hello Splunkers,
I am fed up with an error when trying to install the microsoft could services add-on on my search head:
First, I must mention that I work on a distributed environment with:
1 search head
2 indexers with 1 master cluster node
2 forwarders
1 deployment servers
Has stated in the documentation, I currently can't install and collect office data from my forwarders has they are not Heavy forwarders.
From what I understood, the only way I can go further with this is to install it on my SH.
OK now I try to create an input and get the following error:
REST ERROR[1021]: Fail to decrypt the encrypted credential information - not well-formed (invalid token) : line 33, column 42
Here is the full trace:
09-18-2017 17:23:34.118 +0200 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/bin/runScript.py execute': BaseException: REST ERROR[1021]: Fail to decrypt the encrypted credential information - not well-formed (invalid token): line 33, column 42
09-18-2017 17:23:34.128 +0200 ERROR AdminManagerExternal - External handler failed with code '1' and output: 'REST ERROR[1021]: Fail to decrypt the encrypted credential information - not well-formed (invalid token): line 33, column 42'. See splunkd.log for stderr output.
09-18-2017 17:23:48.975 +0200 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/bin/runScript.py execute': Traceback (most recent call last):
09-18-2017 17:23:48.975 +0200 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/bin/runScript.py execute': File "/opt/splunk/bin/runScript.py", line 78, in
09-18-2017 17:23:48.975 +0200 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/bin/runScript.py execute': execfile(REAL_SCRIPT_NAME)
09-18-2017 17:23:48.975 +0200 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/bin/runScript.py execute': File "/opt/splunk/etc/apps/Splunk_TA_microsoft-cloudservices/bin/splunk_ta_ms_o365_rh_server_accounts.py", line 31, in
09-18-2017 17:23:48.975 +0200 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/bin/runScript.py execute': admin.init(base.ResourceHandler(Account), admin.CONTEXT_APP_AND_USER)
09-18-2017 17:23:48.975 +0200 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/bin/runScript.py execute': File "/opt/splunk/lib/python2.7/site-packages/splunk/admin.py", line 129, in init
09-18-2017 17:23:48.975 +0200 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/bin/runScript.py execute': hand.execute(info)
09-18-2017 17:23:48.975 +0200 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/bin/runScript.py execute': File "/opt/splunk/lib/python2.7/site-packages/splunk/admin.py", line 589, in execute
09-18-2017 17:23:48.975 +0200 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/bin/runScript.py execute': if self.requestedAction == ACTION_CREATE: self.handleCreate(confInfo)
09-18-2017 17:23:48.975 +0200 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/bin/runScript.py execute': File "/opt/splunk/etc/apps/Splunk_TA_microsoft-cloudservices/bin/splunktamscs/splunktaucclib/rest_handler/base.py", line 285, in handleCreate
09-18-2017 17:23:48.975 +0200 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/bin/runScript.py execute': args = self.encode(self.callerArgs.data)
09-18-2017 17:23:48.975 +0200 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/bin/runScript.py execute': File "/opt/splunk/etc/apps/Splunk_TA_microsoft-cloudservices/bin/splunktamscs/splunktaucclib/rest_handler/base.py", line 348, in encode
09-18-2017 17:23:48.975 +0200 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/bin/runScript.py execute': args = self._cred_mgmt.encrypt(tanzaName, args)
09-18-2017 17:23:48.975 +0200 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/bin/runScript.py execute': File "/opt/splunk/etc/apps/Splunk_TA_microsoft-cloudservices/bin/splunktamscs/splunktaucclib/rest_handler/cred_mgmt.py", line 75, in encrypt
09-18-2017 17:23:48.975 +0200 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/bin/runScript.py execute': cred_data = self.decrypt(stanzaName, {})
09-18-2017 17:23:48.975 +0200 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/bin/runScript.py execute': File "/opt/splunk/etc/apps/Splunk_TA_microsoft-cloudservices/bin/splunktamscs/splunktaucclib/rest_handler/cred_mgmt.py", line 123, in decrypt
09-18-2017 17:23:48.975 +0200 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/bin/runScript.py execute': shouldRaise=True)
09-18-2017 17:23:48.975 +0200 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/bin/runScript.py execute': File "/opt/splunk/etc/apps/Splunk_TA_microsoft-cloudservices/bin/splunktamscs/splunktaucclib/rest_handler/error_ctl.py", line 149, in ctl
09-18-2017 17:23:48.975 +0200 ERROR ScriptRunner - stderr from '/opt/splunk/bin/python /opt/splunk/bin/runScript.py execute': raise BaseException(err)
Another thing is, when going on the Troubleshooting page of the Add-on, it shows warning icons saying from my indexers:
REST Processor: Failed to fetch REST endpoint uri=https://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_microsoft-cloudservices/configs/conf-splunk_ta_ms_o365_server_management_api_inputs?count=0 from server https://127.0.0.1:8089. Check that the URI path provided exists in the REST API.
As well as:
Unexpected status for to fetch REST endpoint uri=https://127.0.0.1:8089/servicesNS/nobody/Splunk_TA_microsoft-cloudservices/configs/conf-splunk_ta_ms_o365_server_management_api_inputs?count=0 from server=https://127.0.0.1:8089 - Not Found
I clearly don't understand any of these three error messages (the one when trying to create an input as well as the two from my indexers). Why am I getting an error from my indexers as they don't interfer with this installation ?
A help would be really appreciated guys !
Thanks a lot
Cheers
↧