All Apps and Add-ons

Splunk Connect for Zoom on Windows Heavy Forwarder

joelhasler
New Member

Our Heavy Forwarder runs on Windows Server 2016.

We currently have Splunk 7.3 Enterprise.

We installed the Splunk Connect for Zoom Version 1.0.1

We configured everything based on the documentation but see that our heavy forwarder do not listen on port 4443.

We have a test heavy forwarder, which is running under linux and there it is working. The netstat command shows the process 20318 is associated with the listening port 4443. This process zoom_input.py. See detailed ps entry below:

root 20318 0.0 0.1 244900 25492 ? Sl Aug25 16:07 /opt/splunk/bin/python3.7 /opt/splunk/etc/apps/Splunk_Connect_zoom/bin/zoom_input.py

Now our question is what we need to do that this is also working under windows. I do not see that the app is not supported for windows Heavy forwarders. 

Many thanks

Regards Joël

Labels (3)
0 Karma

joelhasler
New Member

I see the following error in the zoom_input.log 

2020-10-30 13:17:25,328 ERROR Execution failed
Traceback (most recent call last):
File "C:\Program Files\Splunk\etc\apps\Splunk_Connect_zoom\bin\modular_input\modular_input_base_class.py", line 1096, in execute
self.do_run(in_stream, log_exception_and_continue=True)
File "C:\Program Files\Splunk\etc\apps\Splunk_Connect_zoom\bin\modular_input\modular_input_base_class.py", line 965, in do_run
if ServerInfo.is_shc_captain(input_config.session_key) == False:
File "C:\Program Files\Splunk\etc\apps\Splunk_Connect_zoom\bin\modular_input\shortcuts.py", line 31, in wrapper
return function(*args, **kwargs)
File "C:\Program Files\Splunk\etc\apps\Splunk_Connect_zoom\bin\modular_input\server_info.py", line 154, in is_shc_captain
if not cls.is_on_shc(session_key):
File "C:\Program Files\Splunk\etc\apps\Splunk_Connect_zoom\bin\modular_input\shortcuts.py", line 31, in wrapper
return function(*args, **kwargs)
File "C:\Program Files\Splunk\etc\apps\Splunk_Connect_zoom\bin\modular_input\server_info.py", line 111, in is_on_shc
except splunk.ResourceNotFound:
NameError: global name 'splunk' is not defined

Many thanks for your help

Regards,

Joël

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...