All Apps and Add-ons

Data stopped being ingested via "Splunk add-on for Microsoft Office 365": SSLError

mlevsh
Builder

Hi,
We are running Splunk Enterprise version 7.2.9.1 on our Splunk environment.

We installed and configured Splunk add-on for Microsoft Office 365 (splunk_ta_o365) version 2.0.1 and were getting data successfully until few days ago. 

The error that we see is the following:


 

2020-06-16 10:33:31,183 level=ERROR pid=12626 tid=MainThread logger=splunk_ta_o365.modinputs.management_activity pos=utils.py:wrapper:67 | datainput="splunkqa_ma_auditexchange" start_time=1592318010 | message="Data input was interrupted by an unhandled exception."
...
SSLError: HTTPSConnectionPool(host='login.microsoftonline.com', port=443): Max retries exceeded with url: /12345678c-1234-5ab6-9ab12-a12bc34de5fg/oauth2/token (Caused by SSLError(SSLError(1, u'[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed (_ssl.c:741)'),))

 


Will appreciate your guidance on how to handle this kind of errors for Splunk add-on for MS Office 365.

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...