All Apps and Add-ons

Splunk Add-on for EMC VNX: How do I resolve tags.conf errors "Value in stanza [eventtype=..]...not URI encoded"?

RyoTakebayashi
Explorer

How do I resolve this tags.conf problem?

[root@splunk-122 ~]# /root/splunk/bin/splunk restart
Stopping splunkd...
Shutting down.  Please wait, as this may take a few minutes.
...                                                        [  OK  ]
Stopping splunk helpers...
                                                           [  OK  ]
Done.

Splunk> Take the sh out of IT.

Checking prerequisites...
        Checking http port [8000]: open
        Checking mgmt port [8089]: open
        Checking appserver port [127.0.0.1:8065]: open
        Checking kvstore port [8191]: open
        Checking configuration...  Done.
        Checking critical directories...        Done
        Checking indexes...
                Validated: _audit _internal _introspection _thefishbucket history main summary
        Done
        Checking filesystem compatibility...  Done
        Checking conf files for problems...
                Value in stanza [eventtype=vnx:block:processorPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 3 not URI encoded: eventtype = vnx:block:processorPerf
                Value in stanza [eventtype=vnx:block:drivePerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 7 not URI encoded: eventtype = vnx:block:drivePerf
                Value in stanza [eventtype=vnx:block:devicePerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 11 not URI encoded: eventtype = vnx:block:devicePerf
                Value in stanza [eventtype=vnx:file:systemCachePerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 15 not URI encoded: eventtype = vnx:file:systemCachePerf
                Value in stanza [eventtype=vnx:file:systemPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 19 not URI encoded: eventtype = vnx:file:systemPerf
                Value in stanza [eventtype=vnx:file:fileSystemPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 23 not URI encoded: eventtype = vnx:file:fileSystemPerf
                Value in stanza [eventtype=vnx:file:diskVolumePerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 27 not URI encoded: eventtype = vnx:file:diskVolumePerf
                Value in stanza [eventtype=vnx:file:netDevicePerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 31 not URI encoded: eventtype = vnx:file:netDevicePerf
                Value in stanza [eventtype=vnx:file:cifsPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 35 not URI encoded: eventtype = vnx:file:cifsPerf
                Value in stanza [eventtype=vnx:file:cifsServerPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 39 not URI encoded: eventtype = vnx:file:cifsServerPerf
                Value in stanza [eventtype=vnx:file:cifsClientPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 43 not URI encoded: eventtype = vnx:file:cifsClientPerf
                Value in stanza [eventtype=vnx:file:cifsUserPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 47 not URI encoded: eventtype = vnx:file:cifsUserPerf
                Value in stanza [eventtype=vnx:file:cifsOpsPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 51 not URI encoded: eventtype = vnx:file:cifsOpsPerf
                Value in stanza [eventtype=vnx:file:nfsPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 55 not URI encoded: eventtype = vnx:file:nfsPerf
                Value in stanza [eventtype=vnx:file:nfsExportPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 59 not URI encoded: eventtype = vnx:file:nfsExportPerf
                Value in stanza [eventtype=vnx:file:nfsClientPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 63 not URI encoded: eventtype = vnx:file:nfsClientPerf
                Value in stanza [eventtype=vnx:file:nfsUserPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 67 not URI encoded: eventtype = vnx:file:nfsUserPerf
                Value in stanza [eventtype=vnx:file:nfsGroupPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 71 not URI encoded: eventtype = vnx:file:nfsGroupPerf
                Value in stanza [eventtype=vnx:file:nfsOpsPerf] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 75 not URI encoded: eventtype = vnx:file:nfsOpsPerf
                Value in stanza [eventtype=vnx:block:systemOs] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 81 not URI encoded: eventtype = vnx:block:systemOs
                Value in stanza [eventtype=vnx:block:systemCpu] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 85 not URI encoded: eventtype = vnx:block:systemCpu
                Value in stanza [eventtype=vnx:block:systemMemory] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 89 not URI encoded: eventtype = vnx:block:systemMemory
                Value in stanza [eventtype=vnx:block:systemInventory] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 93 not URI encoded: eventtype = vnx:block:systemInventory
                Value in stanza [eventtype=vnx:block:device] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 97 not URI encoded: eventtype = vnx:block:device
                Value in stanza [eventtype=vnx:block:drive] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 102 not URI encoded: eventtype = vnx:block:drive
                Value in stanza [eventtype=vnx:block:raidGroup] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 107 not URI encoded: eventtype = vnx:block:raidGroup
                Value in stanza [eventtype=vnx:block:storagePool] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 112 not URI encoded: eventtype = vnx:block:storagePool
                Value in stanza [eventtype=vnx:file:fileSystem] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 117 not URI encoded: eventtype = vnx:file:fileSystem
                Value in stanza [eventtype=vnx:file:checkpoint] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 122 not URI encoded: eventtype = vnx:file:checkpoint
                Value in stanza [eventtype=vnx:file:vpfs] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 127 not URI encoded: eventtype = vnx:file:vpfs
                Value in stanza [eventtype=vnx:file:storagePool] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 132 not URI encoded: eventtype = vnx:file:storagePool
                Value in stanza [eventtype=vnx:file:disk] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 137 not URI encoded: eventtype = vnx:file:disk
                Value in stanza [eventtype=vnx:file:userQuota] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 142 not URI encoded: eventtype = vnx:file:userQuota
                Value in stanza [eventtype=vnx:file:groupQuota] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 147 not URI encoded: eventtype = vnx:file:groupQuota
                Value in stanza [eventtype=vnx:file:treeQuota] in /root/splunk/etc/apps/Splunk_TA_emc-vnx/default/tags.conf, line 152 not URI encoded: eventtype = vnx:file:treeQuota
                Your indexes and inputs configurations are not internally consistent. For more information, run 'splunk btool check --debug'
        Done
        Checking default conf files for edits...
        Validating installed files against hashes from '/root/splunk/splunk-6.3.0-aa7d4b1ccb80-linux-2.6-x86_64-manifest'
        All installed files intact.
        Done
All preliminary checks passed.

Starting splunk server daemon (splunkd)...
Done
                                                           [  OK  ]

Waiting for web server at http://127.0.0.1:8000 to be available.. Done


If you get stuck, we're here to help.
Look for answers here: http://docs.splunk.com

The Splunk web interface is at http://splunk-122.nosbizlab.local:8000

[root@splunk-122 ~]#


[root@splunk-122 splunk]# tail -f -n 0 ta_vnx.log data_loader.log splunkd.log |grep -e vnx -e VNX
==> ta_vnx.log <==
==> ta_vnx.log <==
2015-11-16 18:16:08,451 INFO 140255710451456 - Start VNX TA
2015-11-16 18:16:09,491 INFO 140255710451456 - No data collection for VNX is found in the inputs.conf. Do nothing and Quit the TA
11-16-2015 18:16:29.081 +0900 INFO  SpecFiles - Found external scheme definition for stanza "vnx_data_loader://" with 7 parameters: network_addr, network_addr2, username, password, platform, site, loglevel
11-16-2015 18:16:29.386 +0900 INFO  ModularInputs - Introspection setup completed for scheme "vnx_data_loader".
11-16-2015 18:16:29.504 +0900 INFO  ModularInputs - No stanzas found for scheme "vnx_data_loader" in inputs.conf at script (re)start.
11-16-2015 18:16:29.504 +0900 INFO  ExecProcessor - New scheduled exec process: python /root/splunk/etc/apps/Splunk_TA_emc-vnx/bin/vnx_data_loader.py
==> ta_vnx.log &<==
2015-11-16 18:16:32,206 INFO 139959737960192 - Start VNX TA
==> ta_vnx.log <==
2015-11-16 18:16:33,252 INFO 139959737960192 - No data collection for VNX is found in the inputs.conf. Do nothing and Quit the TA
==> ta_vnx.log <==
2015-11-16 18:17:32,219 INFO 140035310089984 - Start VNX TA
2015-11-16 18:17:33,262 INFO 140035310089984 - No data collection for VNX is found in the inputs.conf. Do nothing and Quit the TA
1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

Hi, this is a known bug introduced by more aggressive error-checking in the core; we have it on the backlog for fixing, but haven't scheduled it.

View solution in original post

0 Karma

christinetran
Engager

To resolve the "not URL encoded" error, modify your $SPLUNK_HOME/etc/apps/Splunk_TA_emc-vnx/default/tags.conf and change all ":" (colon) to "%3A" -- %3A is the URL encoded representation for the colon. Until Splunk fixes the aggressive error checking, this will shut up the annoying error.

In vim edit mode:

:%s/:/\%3A/g

To resolve the "No data collection for VNX is found in the inputs.conf. Do nothing and Quit the TA" error, you need to modify your $SPLUNK_HOME/etc/apps/Splunk_TA_emc-vnx/local/inputs.conf to specify the IP address and user credential needed to read your EMC VNX. It looks like this:

[vnx_data_loader://EMC_GUID]
network_addr = x.y.z.zz
username = plaintextusername
password = plaintextpassword
platform = VNX Block or File

jcoates_splunk
Splunk Employee
Splunk Employee

Hi, this is a known bug introduced by more aggressive error-checking in the core; we have it on the backlog for fixing, but haven't scheduled it.

0 Karma

shingle
New Member

I'm having the same issue six months later:
No data collection for VNX is found in the inputs.conf. Do nothing and Quit the TA

Can anybody recommend a way to work around this bug?

0 Karma

RyoTakebayashi
Explorer

I understand what you wrote. Thank you very much for your kindeness.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...