All Apps and Add-ons

Troubleshooting EMC Isilon App for Splunk Entreprise

gpareesi11
Path Finder

Hi,
I'm currently running Splunk Enterprise 6.4.3 on Windows 2012r2, almost everything running smoothly except EMC Isilon App & Add-On.
I'm currently trying to solve why I'm unable to get these apps working properly.

I have install both Application EMC Isilon Add-on for Splunk Enterprise & EMC Isilon App for Splunk Enterprise.

I have configure the Add-on, using IP of one Node of my Isilon Cluster and using Admin account. Configuration look simple and don't give any error message.

I did not see any sourcetype from EMC in Splunk, emc:isilon:rest or emc:isilon:syslog

I'm troubleshooting the problem using : index=_internal component="ExecProcessor" "EMC Isilon Error:" and here what I see:

message from "python "C:\Program Files\Splunk\etc\apps\TA_EMC-Isilon\bin\isilon.py"" EMC Isilon Error: Could not get TA_EMC-Isilon credentials from splunk. Error: 'str' object has no attribute 'os_startIndex'

message from "python "C:\Program Files\Splunk\etc\apps\TA_EMC-Isilon\bin\isilon.py"" EMC Isilon Error: Error while getting session validity for authentication. EMC Isilon Error: Could not get TA_EMC-Isilon credentials from splunk. Error: 'str' object has no attribute 'os_startIndex'

*message from "python "C:\Program Files\Splunk\etc\apps\TA_EMC-Isilon\bin\isilon.py"" EMC Isilon Error: Looks like an error while getting count for endpoint 401 Client Error: Authorization Required : https://xxx.xxx.xxx.xxx:8080/platform/1/statistics/current?key=node.sensor.fan.rpms.$get_count$&devi... *

These two errors message came back constently and not data from Isilon is in Splunk.

Thanks

0 Karma

pjvarjani
Path Finder

Hi,
Few quick questions:

  1. Have you upgraded your Isilon TA from 1.0 to 2.0 ?

  2. Can you please check if file $SPLUNK_HOME/etc/apps/TA_EMC-Isilon/local/passwords.conf is created and contains the node information you have provided during setup?

  3. IS there a last_session_call_info.pos file created (and not empty) at $SPLUNK_HOME/etc/apps/TA_EMC-Isilon/local/ directory ?

Thanks

0 Karma

gpareesi11
Path Finder

Hi,

  1. I'm running version 2.0 installed from scratch, never used 1.0.
  2. Yes the password.conf is present and contain encrypted password
  3. Only *.conf file in the local folder, there no last_session_call_info.pos in the folder.

Thank you

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...