Splunk operator not working

adamfadamf Member Posts: 34 Contributor I
edited December 2018 in Help

Hello,

 

I am trying to read data from a local Splunk server using the new Splunk operator in RapidMiner Studio.  I have verified that I can conect to and access the Splunk server outside of RapidMiner from my browser (i.e., I know my login credentials are good, connectivity is fine, etc.).  But, when I try to run a simple process in Studio that uses the Splunk operator, I receive the following error message:

 

“Splunk Connection Failure: Error connecting to the Splunk server: No appropriate protocol (protocol is disabled or cipher suites are inappropriate).”

 

Any help would be appreciated!

 

Tagged:

Answers

  • Marco_BoeckMarco_Boeck Administrator, Moderator, Employee, Member, University Professor Posts: 1,993 RM Engineering

    Hi,

     

    We released Splunk Extension version 8.2.0 today, which improves a few things and should also fix this issue.

     

    Regards,

    Marco

  • adamfadamf Member Posts: 34 Contributor I

    Hi Marco,

     

    Thanks for the response and update.  I downloaded and installed the new Splunk connector.  Unfortunately, I am getting a new/different error (see attached screen shot).  Can you help me troubleshoot?

     

    Regards,


    Adam

  • Thomas_OttThomas_Ott RapidMiner Certified Analyst, RapidMiner Certified Expert, Member Posts: 1,761 Unicorn

    @adamf to get someone's attention on the threads, use the '@' and their name. Threads get buried quickly here. 

  • jczogallajczogalla Employee, Member Posts: 144 RM Engineering

    HI @adamf,

    sorry that the thread got burried. Can you provide your studio log file please? From the screenshot alone I would think that there is some network problem (firewall, bad connection...), but the log file might clear this up. Also, which Splunk server version are you using?

    Cheers

    Jan

  • adamfadamf Member Posts: 34 Contributor I

    Hello @jczogal,

     

    Attached is the RapidMiner Studio log file. 

     

    I am using Splunk v7.0.2, build 03bbabbd5c0f.

     

    - Adam

     

  • jczogallajczogalla Employee, Member Posts: 144 RM Engineering

    Hi @adamf,

     

    I first thought it might be related to the TLS protocols used, I'm not actually sure if that is the case here. Can you maybe also share your process/the splunk query that causes the issue? If you just set the query to "*" and the limit parameter to 10, are there any results or the same error? We are already looking into some issue where some queries don't work.

     

    Cheers

    Jan

  • adamfadamf Member Posts: 34 Contributor I

    Hi Jan,

     

    Same error, even with your suggested query.  Screen shot attached.

     

    - Adam

     

  • adamfadamf Member Posts: 34 Contributor I

    Hi Jan,

     

    I found the problem.  Totally "user error".  I made a mistake with the port number when I set up the connection to the server.  I am sorry to have made you invest any cycles trying to troubleshoot!

     

    Regards,

     

    - Adam

     

  • jczogallajczogalla Employee, Member Posts: 144 RM Engineering

    Hi Adam,

     

    no problem. :) As I said, we are investigating some other failing queries anyway. But I'm glad that it is working now for you.

     

    Cheers

    Jan

Sign In or Register to comment.