All Apps and Add-ons

SAS Token Encyryption Errors

pkeller
Contributor

When using the app on a heavy forwarder to configure a Storage Account with a SAS token we're getting the following error. We've tried generating 2 different SAS keys and yet we still get the same Splunk rejection. The token is valid, yet Splunk appears to be incapable of handling it.

We're trying to first set this up under Configuration -> Add Azure Storage Account

The token generated is formatted like the string below ...

?sv=YYYY-MM-DD&sig=xx9xx22%2xX1x0xXxXxx%2xxXXXx0XXXxXxxxXXx00xxXX%3D&se=YYYY-YY-YYTNN%3x00%3c00x&srt=sco&ss=bfqt&sp=rl

alt text

0 Karma

pkeller
Contributor

This is now resolved. I did a fresh install of the Add-On and went through the storage account provisioning again and everything worked fine. This likely was due to my having copied an already configured app from our test environment to the production environment and that decryption was probably expecting a different secret key.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...