All Apps and Add-ons

Microsoft Azure Active Directory Add-on for Splunk: Customized key cannot be found

wstarowicz
Path Finder

Hi, for a few days I haven't gotten any logs.
After enabling debug, I see something like " Customized key cannot be found".
What does it mean?

schelms
Engager

I started receiving this error recently. It seems that when I have 2 or more inputs (either Signins, Audit, or Users) then I get this error. However, if I delete all but a single input then it works. So temporarily I can only have one working input.

I think the issue may have to do with the rotation of the Auth token when making the API call but that is just my guess.

0 Karma

jaxjohnny2000
Builder

maybe. I have the same issue after my initial key expired. It does not like the second one.

0 Karma

jaxjohnny2000
Builder

Problem no longer exists after upgrading to 2.0.0 for me.

0 Karma

brianbye
Explorer

Im having the same issue. Anyone figure out a permanent solution?

0 Karma

jaxjohnny2000
Builder

Same issue here. My Client Certificate expired. I created a new one. Then may other errors, but this is the most pervasive.

tid=MainThread file=setup_util.py:log_info:114 | Customized key can not be found

0 Karma

ylucena
Explorer

I am having the same problem! Did you guys figured that out?

0 Karma

jwalzerpitt
Influencer

+1 as also having the issue

Any idea as to why the issue and if a solution exists?

0 Karma

DavidHourani
Super Champion

Hi @wstarowicz, what errors do you have exactly in _internal regarding this issue, could you give us some outputs here ?

0 Karma

wstarowicz
Path Finder

It's a bit strange. Earlier I had 429 (since few days). These started to appear (as INFO) after few disabling/enabling of the input. Now it started working (logs are downloaded). So this is rather question now what does it mean.

2019-06-21 11:52:40,409 DEBUG pid=11844 tid=MainThread file=connectionpool.py:_new_conn:809 | Starting new HTTPS connection (1): login.microsoftonline.com
2019-06-21 11:52:40,690 DEBUG pid=11844 tid=MainThread file=connectionpool.py:_make_request:400 | https://login.microsoftonline.com:443 "POST /tenant_id/oauth2/v2.0/token HTTP/1.1" 200 1516
2019-06-21 11:52:40,693 DEBUG pid=11844 tid=MainThread file=base_modinput.py:log_debug:286 | Sign-in URL used: https://graph.microsoft.com/beta/auditLogs/signIns?$orderby=createdDateTime&$filter=createdDateTime+...
2019-06-21 11:52:40,693 INFO pid=11844 tid=MainThread file=setup_util.py:log_info:114 | Customized key can not be found

0 Karma

DavidHourani
Super Champion

Which Splunk version are you using ? Maybe there was an incompatibility. Also did you restart Splunk after installing the ad-on ?

0 Karma

wstarowicz
Path Finder

Hi, yes I did. I'm running version 7.2.4.

0 Karma

DavidHourani
Super Champion

That should be okay, it's supported : Splunk Versions: 7.3, 7.2, 7.1, 7.0, 6.6. Should be some bug that got flushed with the enable-disable.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...