All Apps and Add-ons

SAS Token Encyryption Errors

pkeller
Contributor

When using the app on a heavy forwarder to configure a Storage Account with a SAS token we're getting the following error. We've tried generating 2 different SAS keys and yet we still get the same Splunk rejection. The token is valid, yet Splunk appears to be incapable of handling it.

We're trying to first set this up under Configuration -> Add Azure Storage Account

The token generated is formatted like the string below ...

?sv=YYYY-MM-DD&sig=xx9xx22%2xX1x0xXxXxx%2xxXXXx0XXXxXxxxXXx00xxXX%3D&se=YYYY-YY-YYTNN%3x00%3c00x&srt=sco&ss=bfqt&sp=rl

alt text

0 Karma

pkeller
Contributor

This is now resolved. I did a fresh install of the Add-On and went through the storage account provisioning again and everything worked fine. This likely was due to my having copied an already configured app from our test environment to the production environment and that decryption was probably expecting a different secret key.

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...