Closed hgtok closed 5 months ago
Hi @hgtok, Thanks for flagging this issue, we will investigate this issue and get back to you with some updates by 20-06-2024. Thanks!
Hi @hgtok, Could you please check the function app by updating the WEBSITE_RUN_FROM_PACKAGE with below shared URL in the function app. and let us know the response.
Once updating it, please restart the function app. Please let us know if your issue gets resolved. Thanks!
Works! We can see data ingested now. However, we still spot some [Error] showing up in the logs. Pls advise.
2024-06-13T08:28:43Z [Verbose] [HostMonitor] Checking worker statuses (Count=1) 2024-06-13T08:28:43Z [Verbose] [HostMonitor] Worker status: ID=3417dee0-3037-4ae3-ab42-2d3dd6f5b76f, Latency=2ms 2024-06-13T08:28:43Z [Verbose] [HostMonitor] Host process CPU stats (PID 89): History=(0,0,0,0,0), AvgCpuLoad=0, MaxCpuLoad=0 2024-06-13T08:28:43Z [Verbose] [HostMonitor] Host process CPU stats (PID 60): History=(1,1,0,3,2), AvgCpuLoad=1, MaxCpuLoad=3 2024-06-13T08:28:43Z [Verbose] [HostMonitor] Host aggregate CPU load 1 2024-06-13T08:28:43Z [Information] Executing StatusCodeResult, setting HTTP status code 200 2024-06-13T08:28:49Z [Verbose] Received request to drain the host 2024-06-13T08:28:57Z [Verbose] [HostMonitor] Checking worker statuses (Count=1) 2024-06-13T08:28:57Z [Verbose] [HostMonitor] Worker status: ID=3417dee0-3037-4ae3-ab42-2d3dd6f5b76f, Latency=5ms 2024-06-13T08:28:57Z [Verbose] [HostMonitor] Host process CPU stats (PID 89): History=(0,0,0,0,0), AvgCpuLoad=0, MaxCpuLoad=0 2024-06-13T08:28:57Z [Verbose] [HostMonitor] Host process CPU stats (PID 60): History=(0,0,2,0,1), AvgCpuLoad=1, MaxCpuLoad=2 2024-06-13T08:28:57Z [Verbose] [HostMonitor] Host aggregate CPU load 1 2024-06-13T08:28:57Z [Information] Executing StatusCodeResult, setting HTTP status code 200 2024-06-13T08:29:06Z [Information] Host lock lease acquired by instance ID '0000000000000000000000004D4E09B4'. 2024-06-13T08:29:06Z [Verbose] Function 'queue_trigger_wb_poison' will wait 60000 ms before polling queue 'workbench-queue-poison'. 2024-06-13T08:29:10Z [Verbose] [HostMonitor] Checking worker statuses (Count=1) 2024-06-13T08:29:10Z [Verbose] [HostMonitor] Worker status: ID=3417dee0-3037-4ae3-ab42-2d3dd6f5b76f, Latency=1ms 2024-06-13T08:29:10Z [Verbose] [HostMonitor] Host process CPU stats (PID 89): History=(0,0,0,0,0), AvgCpuLoad=0, MaxCpuLoad=0 2024-06-13T08:29:10Z [Verbose] [HostMonitor] Host process CPU stats (PID 60): History=(1,2,0,1,1), AvgCpuLoad=1, MaxCpuLoad=2 2024-06-13T08:29:10Z [Verbose] [HostMonitor] Host aggregate CPU load 1 2024-06-13T08:29:10Z [Information] Executing StatusCodeResult, setting HTTP status code 200 2024-06-13T08:29:11Z [Verbose] Function 'oat_pipeline_file_poison_qt' will wait 60000 ms before polling queue 'oat-pipeline-file-queue-poison'. 2024-06-13T08:29:17Z [Verbose] Function 'oat_pipeline_file_qt' will wait 60000 ms before polling queue 'oat-pipeline-file-queue'. 2024-06-13T08:29:22Z [Verbose] Poll for function 'queue_trigger_wb' on queue 'workbench-queue' with ClientRequestId '4c4d2ddd-6d66-46c7-99d7-1d04ab1dd184' found 0 messages in 5 ms. 2024-06-13T08:29:22Z [Verbose] Function 'queue_trigger_wb' will wait 60000 ms before polling queue 'workbench-queue'. 2024-06-13T08:29:23Z [Verbose] [HostMonitor] Checking worker statuses (Count=1) 2024-06-13T08:29:23Z [Verbose] [HostMonitor] Worker status: ID=3417dee0-3037-4ae3-ab42-2d3dd6f5b76f, Latency=1ms 2024-06-13T08:29:23Z [Verbose] [HostMonitor] Host process CPU stats (PID 89): History=(0,0,0,1,0), AvgCpuLoad=0.2, MaxCpuLoad=1 2024-06-13T08:29:23Z [Verbose] [HostMonitor] Host process CPU stats (PID 60): History=(1,1,0,1,1), AvgCpuLoad=1, MaxCpuLoad=1 2024-06-13T08:29:23Z [Verbose] [HostMonitor] Host aggregate CPU load 1 2024-06-13T08:29:23Z [Information] Executing StatusCodeResult, setting HTTP status code 200 2024-06-13T08:29:25Z [Verbose] Function 'oat_pipeline_task_qt' will wait 60000 ms before polling queue 'oat-pipeline-task-queue'. 2024-06-13T08:29:28Z [Verbose] Function 'oat_pipeline_task_poison_qt' will wait 60000 ms before polling queue 'oat-pipeline-task-queue-poison'. 2024-06-13T08:29:29Z [Verbose] Function 'queue_trigger_rca' will wait 60000 ms before polling queue 'rca-queue'. 2024-06-13T08:29:36Z [Verbose] [HostMonitor] Checking worker statuses (Count=1) 2024-06-13T08:29:36Z [Verbose] [HostMonitor] Worker status: ID=3417dee0-3037-4ae3-ab42-2d3dd6f5b76f, Latency=1ms 2024-06-13T08:29:36Z [Verbose] [HostMonitor] Host process CPU stats (PID 89): History=(1,0,0,0,0), AvgCpuLoad=0.2, MaxCpuLoad=1 2024-06-13T08:29:36Z [Verbose] [HostMonitor] Host process CPU stats (PID 60): History=(0,2,0,1,1), AvgCpuLoad=1, MaxCpuLoad=2 2024-06-13T08:29:36Z [Verbose] [HostMonitor] Host aggregate CPU load 1 2024-06-13T08:29:36Z [Information] Executing StatusCodeResult, setting HTTP status code 200 2024-06-13T08:29:50Z [Verbose] [HostMonitor] Checking worker statuses (Count=1) 2024-06-13T08:29:50Z [Verbose] [HostMonitor] Worker status: ID=3417dee0-3037-4ae3-ab42-2d3dd6f5b76f, Latency=1ms 2024-06-13T08:29:50Z [Verbose] [HostMonitor] Host process CPU stats (PID 89): History=(0,0,0,0,0), AvgCpuLoad=0, MaxCpuLoad=0 2024-06-13T08:29:50Z [Verbose] [HostMonitor] Host process CPU stats (PID 60): History=(1,0,2,0,0), AvgCpuLoad=1, MaxCpuLoad=2 2024-06-13T08:29:50Z [Verbose] [HostMonitor] Host aggregate CPU load 1 2024-06-13T08:29:50Z [Information] Executing StatusCodeResult, setting HTTP status code 200 2024-06-13T08:30:00Z [Information] Executing 'Functions.timer_trigger' (Reason='Timer fired at 2024-06-13T08:29:59.9997464+00:00', Id=cf0b4c43-be80-4313-97c7-6e46b00befa1) 2024-06-13T08:30:00Z [Verbose] Sending invocation id: 'cf0b4c43-be80-4313-97c7-6e46b00befa1 2024-06-13T08:30:00Z [Verbose] Posting invocation id:cf0b4c43-be80-4313-97c7-6e46b00befa1 on workerId:3417dee0-3037-4ae3-ab42-2d3dd6f5b76f 2024-06-13T08:30:00Z [Information] {"asctime": "2024-06-13 08:30:00,004", "message": "Client-Request-ID=1f91989c-295f-11ef-83f1-00155dcb728c Outgoing request: Method=POST, Path=/Tables, Query={'timeout': None}, Headers={'Content-Type': 'application/json', 'Prefer': 'return-no-content', 'Accept': 'application/json;odata=minimalmetadata', 'DataServiceVersion': '3.0;NetFx', 'MaxDataServiceVersion': '3.0', 'Content-Length': '35', 'x-ms-version': '2018-03-28', 'User-Agent': 'Azure-Storage/1.4.2-None (Python CPython 3.9.19; Linux 5.10.102.2-microsoft-standard)', 'x-ms-client-request-id': '1f91989c-295f-11ef-83f1-00155dcb728c', 'x-ms-date': 'Thu, 13 Jun 2024 08:30:00 GMT', 'Authorization': 'REDACTED'}.", "trace_id": "056f4b66-52a6-4fcb-8707-9ea58e88a6bb", "task_id": "9057da04-0fd6-4069-9fa0-6ffdd331ceab", "version": "TMXDRSentinelAddon/1.1.0", "logger_name": "azure.cosmosdb.table.common.storageclient", "func_name": "_perform_request", "level": "INFO"} 2024-06-13T08:30:00Z [Information] Executing 'Functions.timer_trigger_oat' (Reason='Timer fired at 2024-06-13T08:30:00.0078035+00:00', Id=295f8954-c89a-43c7-8173-ee7d1092c60c) 2024-06-13T08:30:00Z [Verbose] Sending invocation id: '295f8954-c89a-43c7-8173-ee7d1092c60c 2024-06-13T08:30:00Z [Verbose] Posting invocation id:295f8954-c89a-43c7-8173-ee7d1092c60c on workerId:3417dee0-3037-4ae3-ab42-2d3dd6f5b76f 2024-06-13T08:30:00Z [Error] Executed 'Functions.timer_trigger_oat' (Failed, Id=295f8954-c89a-43c7-8173-ee7d1092c60c, Duration=2ms) 2024-06-13T08:30:00Z [Verbose] Function 'timer_trigger_oat' updated status: Last='2024-06-13T08:30:00.0077877+00:00', Next='2024-06-13T08:35:00.0000000+00:00', LastUpdated='2024-06-13T08:30:00.0077877+00:00' 2024-06-13T08:30:00Z [Verbose] Timer for 'timer_trigger_oat' started with interval '00:04:59.9660111'. 2024-06-13T08:30:00Z [Information] {"asctime": "2024-06-13 08:30:00,080", "message": "Client-Request-ID=1f91989c-295f-11ef-83f1-00155dcb728c Receiving Response: Server-Timestamp=Thu, 13 Jun 2024 08:29:59 GMT, Server-Request-ID=ecb216b2-1002-004a-776b-bd3a85000000, HTTP Status Code=409, Message=Conflict, Headers={'cache-control': 'no-cache', 'transfer-encoding': 'chunked', 'content-type': 'application/json;odata=minimalmetadata;streaming=true;charset=utf-8', 'server': 'Windows-Azure-Table/1.0 Microsoft-HTTPAPI/2.0', 'x-ms-request-id': 'ecb216b2-1002-004a-776b-bd3a85000000', 'x-ms-version': '2018-03-28', 'x-content-type-options': 'nosniff', 'preference-applied': 'return-no-content', 'date': 'Thu, 13 Jun 2024 08:29:59 GMT'}.", "trace_id": "056f4b66-52a6-4fcb-8707-9ea58e88a6bb", "task_id": "9057da04-0fd6-4069-9fa0-6ffdd331ceab", "version": "TMXDRSentinelAddon/1.1.0", "logger_name": "azure.cosmosdb.table.common.storageclient", "func_name": "_perform_request", "level": "INFO"} 2024-06-13T08:30:00Z [Error] {"asctime": "2024-06-13 08:30:00,080", "message": "Client-Request-ID=1f91989c-295f-11ef-83f1-00155dcb728c Retry policy did not allow for a retry: Server-Timestamp=Thu, 13 Jun 2024 08:29:59 GMT, Server-Request-ID=ecb216b2-1002-004a-776b-bd3a85000000, HTTP status code=409, Exception=Conflict{\"odata.error\":{\"code\":\"TableAlreadyExists\",\"message\":{\"lang\":\"en-US\",\"value\":\"The table specified already exists.\\nRequestId:ecb216b2-1002-004a-776b-bd3a85000000\\nTime:2024-06-13T08:30:00.0766201Z\"}}}.", "trace_id": "056f4b66-52a6-4fcb-8707-9ea58e88a6bb", "task_id": "9057da04-0fd6-4069-9fa0-6ffdd331ceab", "version": "TMXDRSentinelAddon/1.1.0", "logger_name": "azure.cosmosdb.table.common.storageclient", "func_name": "_perform_request", "level": "ERROR"} 2024-06-13T08:30:00Z [Information] {"asctime": "2024-06-13 08:30:00,080", "message": "Client-Request-ID=1f9d4318-295f-11ef-83f1-00155dcb728c Outgoing request: Method=GET, Path=/XdrConnectorStatus(PartitionKey='last_success_time',RowKey='1e34cfa5-7857-4991-80e9-faf985b61f88'), Query={'$select': None, 'timeout': None}, Headers={'Accept': 'application/json;odata=minimalmetadata', 'DataServiceVersion': '3.0;NetFx', 'MaxDataServiceVersion': '3.0', 'x-ms-version': '2018-03-28', 'User-Agent': 'Azure-Storage/1.4.2-None (Python CPython 3.9.19; Linux 5.10.102.2-microsoft-standard)', 'x-ms-client-request-id': '1f9d4318-295f-11ef-83f1-00155dcb728c', 'x-ms-date': 'Thu, 13 Jun 2024 08:30:00 GMT', 'Authorization': 'REDACTED'}.", "trace_id": "056f4b66-52a6-4fcb-8707-9ea58e88a6bb", "task_id": "9057da04-0fd6-4069-9fa0-6ffdd331ceab", "version": "TMXDRSentinelAddon/1.1.0", "logger_name": "azure.cosmosdb.table.common.storageclient", "func_name": "_perform_request", "level": "INFO"} 2024-06-13T08:30:00Z [Information] {"asctime": "2024-06-13 08:30:00,080", "message": "Client-Request-ID=1f91989c-295f-11ef-83f1-00155dcb728c Operation failed: checking if the operation should be retried. Current retry count=0, Server-Timestamp=Thu, 13 Jun 2024 08:29:59 GMT, Server-Request-ID=ecb216b2-1002-004a-776b-bd3a85000000, HTTP status code=409, Exception=Conflict{\"odata.error\":{\"code\":\"TableAlreadyExists\",\"message\":{\"lang\":\"en-US\",\"value\":\"The table specified already exists.\\nRequestId:ecb216b2-1002-004a-776b-bd3a85000000\\nTime:2024-06-13T08:30:00.0766201Z\"}}}.", "trace_id": "056f4b66-52a6-4fcb-8707-9ea58e88a6bb", "task_id": "9057da04-0fd6-4069-9fa0-6ffdd331ceab", "version": "TMXDRSentinelAddon/1.1.0", "logger_name": "azure.cosmosdb.table.common.storageclient", "func_name": "_perform_request", "level": "INFO"} 2024-06-13T08:30:00Z [Information] {"asctime": "2024-06-13 08:30:00,116", "message": "Client-Request-ID=1f9d4318-295f-11ef-83f1-00155dcb728c Receiving Response: Server-Timestamp=Thu, 13 Jun 2024 08:29:59 GMT, Server-Request-ID=ecb216b5-1002-004a-786b-bd3a85000000, HTTP Status Code=200, Message=OK, Headers={'cache-control': 'no-cache', 'transfer-encoding': 'chunked', 'content-type': 'application/json;odata=minimalmetadata;streaming=true;charset=utf-8', 'etag': 'W/\"datetime\\'2024-06-13T08%3A25%3A01.0941678Z\\'\"', 'server': 'Windows-Azure-Table/1.0 Microsoft-HTTPAPI/2.0', 'x-ms-request-id': 'ecb216b5-1002-004a-786b-bd3a85000000', 'x-ms-version': '2018-03-28', 'x-content-type-options': 'nosniff', 'date': 'Thu, 13 Jun 2024 08:29:59 GMT'}.", "trace_id": "056f4b66-52a6-4fcb-8707-9ea58e88a6bb", "task_id": "9057da04-0fd6-4069-9fa0-6ffdd331ceab", "version": "TMXDRSentinelAddon/1.1.0", "logger_name": "azure.cosmosdb.table.common.storageclient", "func_name": "_perform_request", "level": "INFO"} 2024-06-13T08:30:00Z [Information] {"asctime": "2024-06-13 08:30:00,116", "message": "start to poll workbench events from 2024-06-13T08:25:00.000Z to 2024-06-13T08:30:00.000Z.", "trace_id": "056f4b66-52a6-4fcb-8707-9ea58e88a6bb", "task_id": "9057da04-0fd6-4069-9fa0-6ffdd331ceab", "version": "TMXDRSentinelAddon/1.1.0", "logger_name": "root", "func_name": "main", "level": "INFO"} 2024-06-13T08:30:00Z [Information] {"asctime": "2024-06-13 08:30:00,118", "message": "Get workbench list url: https://api.sg.xdr.trendmicro.com/v2.0/siem/events", "trace_id": "4d71b871-b7fb-469b-8ed1-c76d5865c399", "task_id": "9057da04-0fd6-4069-9fa0-6ffdd331ceab", "version": "TMXDRSentinelAddon/1.1.0", "logger_name": "root", "func_name": "get_workbench_list", "level": "INFO"} 2024-06-13T08:30:00Z [Information] {"asctime": "2024-06-13 08:30:00,478", "message": "Get workbench list response: {\"info\":{\"code\":3008000,\"msg\":\"Retrieve workbench summary information successfully.\"},\"data\":{\"totalCount\":0,\"modelList\":[\"Demo - Copying of NTDS File\",\"Demo - Credential Dumping via Registry\",\"Disabling of Gatekeeper\",\"Eicar Test File Detection\",\"Possible Brute Force via Multiple Failed Logons via Windows Event\",\"Possible Disabling of Antivirus Software\",\"Suspicious Multiple Failed Logons via Windows Event\",\"Suspicious Ransomware Behavior\",\"Targeted Attack Detection: Fileless Credential Dumping\",\"Unknown Threat Detection and Mitigation via Predictive Machine Learning\",\"[Heuristic Attribute] Backdoor File Detection\",\"[Heuristic Attribute] Impair Defenses\",\"[Heuristic Attribute] Possible Unsecured Credentials\",\"[Heuristic Attribute] Trojan Spy File Detection\"],\"workbenchRecords\":[]}}Get workbench list trace: task id: 9057da04-0fd6-4069-9fa0-6ffdd331ceab, trace id: 4d71b871-b7fb-469b-8ed1-c76d5865c399.", "trace_id": "4d71b871-b7fb-469b-8ed1-c76d5865c399", "task_id": "9057da04-0fd6-4069-9fa0-6ffdd331ceab", "version": "TMXDRSentinelAddon/1.1.0", "logger_name": "root", "func_name": "get_workbench_list", "level": "INFO"} 2024-06-13T08:30:00Z [Information] {"asctime": "2024-06-13 08:30:00,480", "message": "0 workbench events received.", "trace_id": "4d71b871-b7fb-469b-8ed1-c76d5865c399", "task_id": "9057da04-0fd6-4069-9fa0-6ffdd331ceab", "version": "TMXDRSentinelAddon/1.1.0", "logger_name": "root", "func_name": "main", "level": "INFO"} 2024-06-13T08:30:00Z [Information] {"asctime": "2024-06-13 08:30:00,481", "message": "Client-Request-ID=1fda65d6-295f-11ef-83f1-00155dcb728c Outgoing request: Method=MERGE, Path=/XdrConnectorStatus(PartitionKey='last_success_time',RowKey='1e34cfa5-7857-4991-80e9-faf985b61f88'), Query={'timeout': None}, Headers={'Content-Type': 'application/json', 'Accept': 'application/json;odata=minimalmetadata', 'DataServiceVersion': '3.0;NetFx', 'MaxDataServiceVersion': '3.0', 'Content-Length': '136', 'x-ms-version': '2018-03-28', 'User-Agent': 'Azure-Storage/1.4.2-None (Python CPython 3.9.19; Linux 5.10.102.2-microsoft-standard)', 'x-ms-client-request-id': '1fda65d6-295f-11ef-83f1-00155dcb728c', 'x-ms-date': 'Thu, 13 Jun 2024 08:30:00 GMT', 'Authorization': 'REDACTED'}.", "trace_id": "4d71b871-b7fb-469b-8ed1-c76d5865c399", "task_id": "9057da04-0fd6-4069-9fa0-6ffdd331ceab", "version": "TMXDRSentinelAddon/1.1.0", "logger_name": "azure.cosmosdb.table.common.storageclient", "func_name": "_perform_request", "level": "INFO"} 2024-06-13T08:30:00Z [Information] {"asctime": "2024-06-13 08:30:00,493", "message": "Client-Request-ID=1fda65d6-295f-11ef-83f1-00155dcb728c Receiving Response: Server-Timestamp=Thu, 13 Jun 2024 08:29:59 GMT, Server-Request-ID=ecb216f7-1002-004a-2f6b-bd3a85000000, HTTP Status Code=204, Message=No Content, Headers={'cache-control': 'no-cache', 'content-length': '0', 'etag': 'W/\"datetime\\'2024-06-13T08%3A30%3A00.4852035Z\\'\"', 'server': 'Windows-Azure-Table/1.0 Microsoft-HTTPAPI/2.0', 'x-ms-request-id': 'ecb216f7-1002-004a-2f6b-bd3a85000000', 'x-ms-version': '2018-03-28', 'x-content-type-options': 'nosniff', 'date': 'Thu, 13 Jun 2024 08:29:59 GMT'}.", "trace_id": "4d71b871-b7fb-469b-8ed1-c76d5865c399", "task_id": "9057da04-0fd6-4069-9fa0-6ffdd331ceab", "version": "TMXDRSentinelAddon/1.1.0", "logger_name": "azure.cosmosdb.table.common.storageclient", "func_name": "_perform_request", "level": "INFO"} 2024-06-13T08:30:01Z [Information] Executed 'Functions.timer_trigger' (Succeeded, Id=cf0b4c43-be80-4313-97c7-6e46b00befa1, Duration=644ms) 2024-06-13T08:30:01Z [Verbose] Function 'timer_trigger' updated status: Last='2024-06-13T08:30:00.0000000+00:00', Next='2024-06-13T08:35:00.0000000+00:00', LastUpdated='2024-06-13T08:30:00.0000000+00:00' 2024-06-13T08:30:01Z [Verbose] Timer for 'timer_trigger' started with interval '00:04:59.3326092'. 2024-06-13T08:30:03Z [Verbose] [HostMonitor] Checking worker statuses (Count=1) 2024-06-13T08:30:03Z [Verbose] [HostMonitor] Worker status: ID=3417dee0-3037-4ae3-ab42-2d3dd6f5b76f, Latency=1ms 2024-06-13T08:30:03Z [Verbose] [HostMonitor] Host process CPU stats (PID 89): History=(0,0,2,4,0), AvgCpuLoad=1.2, MaxCpuLoad=4 2024-06-13T08:30:03Z [Verbose] [HostMonitor] Host process CPU stats (PID 60): History=(1,1,2,3,1), AvgCpuLoad=2, MaxCpuLoad=3 2024-06-13T08:30:03Z [Verbose] [HostMonitor] Host aggregate CPU load 3 2024-06-13T08:30:03Z [Information] Executing StatusCodeResult, setting HTTP status code 200 2024-06-13T08:30:06Z [Verbose] Function 'queue_trigger_wb_poison' will wait 60000 ms before polling queue 'workbench-queue-poison'. 2024-06-13T08:30:11Z [Verbose] Function 'oat_pipeline_file_poison_qt' will wait 60000 ms before polling queue 'oat-pipeline-file-queue-poison'. 2024-06-13T08:30:17Z [Verbose] Function 'oat_pipeline_file_qt' will wait 60000 ms before polling queue 'oat-pipeline-file-queue'. 2024-06-13T08:30:22Z [Verbose] Poll for function 'queue_trigger_wb' on queue 'workbench-queue' with ClientRequestId '8cc9bc96-48ab-491f-ad79-7334ef309982' found 0 messages in 9 ms. 2024-06-13T08:30:22Z [Verbose] Function 'queue_trigger_wb' will wait 60000 ms before polling queue 'workbench-queue'. 2024-06-13T08:30:25Z [Verbose] Function 'oat_pipeline_task_qt' will wait 60000 ms before polling queue 'oat-pipeline-task-queue'. 2024-06-13T08:30:28Z [Verbose] Function 'oat_pipeline_task_poison_qt' will wait 60000 ms before polling queue 'oat-pipeline-task-queue-poison'. 2024-06-13T08:30:29Z [Verbose] Function 'queue_trigger_rca' will wait 60000 ms before polling queue 'rca-queue'. 2024-06-13T08:31:06Z [Verbose] Function 'queue_trigger_wb_poison' will wait 60000 ms before polling queue 'workbench-queue-poison'. 2024-06-13T08:31:11Z [Verbose] Function 'oat_pipeline_file_poison_qt' will wait 60000 ms before polling queue 'oat-pipeline-file-queue-poison'.
@hgtok, Could you please share the invocation logs with us so we can check for that error. Thanks!
the logs are included in my previous comment. pls take a look.
Comment added here- https://github.com/Azure/Azure-Sentinel/issues/10653#issuecomment-2172790813
Describe the bug Function App failing with ModuleNotFoundError: No module named '_cffi_backend'.
To Reproduce Steps to reproduce the behavior:
Expected behavior No errors and Trend Micro Vision One logs are ingested into Sentinel
Additional context ModuleNotFoundError is one of the first errors. Multiple errors as attached.
Log stream