Closed bmorgenthaler closed 1 year ago
Hello!
I haven't been able to replicate this. Do you currently have a proxy configured and enabled in the add-on settings?
Nope, no proxy is enabled or configured.
Strange.
Looking at this line in your WARN log: __REST_CREDENTIAL__#TA-opnsense#configs/conf-ta_opnsense_settings
:
If you have access to the command line for this instance, can you check the file $SPLUNK_HOME/etc/apps/TA-opnsense/local/passwords.conf
to see if you see a stanza that looks something like this: [credential:__REST_CREDENTIAL__#TA-opnsense#configs/conf-ta_opnsense_account:proxy]
After, would you also just hit the "Save" button on the proxy setting page to see if that will reload the proxy config?
Checking $SPLUNK_HOME/etc/apps/TA-opnsense/local/passwords.conf
and I do not have any proxy entries, the only two entries I have:
[credential:__REST_CREDENTIAL__#TA-opnsense#configs/conf-ta_opnsense_account:monitor``splunk_cred_sep``1:]
password = redacted
[credential:__REST_CREDENTIAL__#TA-opnsense#configs/conf-ta_opnsense_account:monitor``splunk_cred_sep``2:]
password = redacted
Hit save, restarted Splunk, and the warnings still appear every 15 minutes (what I have the inputs set as for polling schedule).
This appears to be an issue with the Splunk Add-on builder scripts used to create this add-on. These scripts expect the proxy credentials to be configured.
I found a workaround to stop these errors from showing up: while leaving the proxy disabled, add a placeholder username and password to the proxy configuration settings page and hit save. No restart is required.
Let me know if this removes the error messages for you.
Yep! That fixed it, I put bogus credentials in and nothing else and the warning disappeared.
Bug description
Running the latest version of the TA and Splunk 9.0.5 my splunkd.log is being inundated with WARN messages get_password failures. Interestingly enough I do appear to be pulling package and other information in through the API. I notice it says
user=proxy
but no proxy is configured for the Input.Related links
TA-opnsense Version
1.5.3
Splunk Version
9.0.5
OPNsense Version
23.1.9