Posted on 02-22-2021 08:12 AM
Hello all,
We recently upgraded the Jamf Pro Add-on for Splunk add-on to version 1.0.6 on our Splunk Cloud IDM which is running Splunk v. 7.2. The Splunk server is also running Python v. 2.7.17.
After the add-on upgrade, data stopped coming in from the Jamf add-on. Below are the errors we're getting, can someone help troubleshoot this? Thanks.
ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/JAMF-Pro-addon-for-splunk/bin/jamf.py" ERRORtostring() got an unexpected keyword argument 'short_empty_elements'
ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/JAMF-Pro-addon-for-splunk/bin/jamf.py" event = helper.new_event(data=ElementTree.tostring(xml_event,encoding="utf-8", method="xml",short_empty_elements=True).decode(), index=index, host=host)
ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/JAMF-Pro-addon-for-splunk/bin/jamf.py" File "/opt/splunk/etc/apps/JAMF-Pro-addon-for-splunk/bin/input_module_jamf.py", line 97, in writeStringTo_Event
ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/JAMF-Pro-addon-for-splunk/bin/jamf.py" File "/opt/splunk/etc/apps/JAMF-Pro-addon-for-splunk/bin/input_module_jamf.py", line 79, in writeStringTo_Event_withParsing
ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/JAMF-Pro-addon-for-splunk/bin/jamf.py" File "/opt/splunk/etc/apps/JAMF-Pro-addon-for-splunk/bin/jamf_pro_addon_for_splunk/aob_py2/modinput_wrapper/base_modinput.py", line 128, in stream_events