Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Errors observed in the JumpCloud Function App #11695

Open
HotdogAndBaloney314 opened this issue Jan 21, 2025 · 37 comments
Open

Errors observed in the JumpCloud Function App #11695

HotdogAndBaloney314 opened this issue Jan 21, 2025 · 37 comments
Assignees
Labels
Connector Connector specialty review needed

Comments

@HotdogAndBaloney314
Copy link

Hi Team,

We've recently used the JumpCloud data connector available in this repository. Logs are now flowing in to Microsoft Sentinel. However, we're seeing 2 errors in the log stream. See below:

Error 1:
2025-01-08T13:10:20Z [Warning] Error response [ea143ec5-5517-4b81-91df-563cdbbe1b0f] 409 The specified container already exists. (00.0s) Server:Windows-Azure-Blob/1.0 Microsoft-HTTPAPI/2.0 x-ms-request-id:f8127057-d01e-0011-7fce-612bae000000 x-ms-client-request-id:ea143ec5-5517-4b81-91df-563cdbbe1b0f x-ms-version:2023-11-03 x-ms-error-code:ContainerAlreadyExists Date:Wed, 08 Jan 2025 13:10:19 GMT Content-Length:230 Content-Type:application/xml

Error 2:
2025-01-21T11:35:07Z [Error] ERROR: Cannot find an overload for "ToString" and the argument count: "1". Exception : Type : System.Management.Automation.MethodException ErrorRecord : Exception : Type : System.Management.Automation.ParentContainsErrorRecordException Message : Cannot find an overload for "ToString" and the argument count: "1". HResult : -2146233087 CategoryInfo : NotSpecified: (:) [], ParentContainsErrorRecordException FullyQualifiedErrorId : MethodCountCouldNotFindBest InvocationInfo : ScriptLineNumber : 136 OffsetInLine : 9 HistoryId : 1 ScriptName : C:\home\site\wwwroot\JCQueueTrigger1\run.ps1 Line : $LastRecordTimestamp = $LastRecordTimeStamp.ToString('yyyy-MM-ddThh:mm:ssZ') Statement : $LastRecordTimestamp = $LastRecordTimeStamp.ToString('yyyy-MM-ddThh:mm:ssZ') PositionMessage : At C:\home\site\wwwroot\JCQueueTrigger1\run.ps1:136 char:9 + $LastRecordTimestamp = $LastRecordTimeStamp.ToString('yyyy-MM … + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ PSScriptRoot : C:\home\site\wwwroot\JCQueueTrigger1 PSCommandPath : C:\home\site\wwwroot\JCQueueTrigger1\run.ps1 CommandOrigin : Internal ScriptStackTrace : at , C:\home\site\wwwroot\JCQueueTrigger1\run.ps1: line 136 TargetSite : System.Object CallSite.Target(System.Runtime.CompilerServices.Closure, System.Runtime.CompilerServices.CallSite, System.Object, System.String) Message : Cannot find an overload for "ToString" and the argument count: "1". Source : Anonymously Hosted DynamicMethods Assembly HResult : -2146233087 StackTrace : at CallSite.Target(Closure, CallSite, Object, String) at System.Dynamic.UpdateDelegates.UpdateAndExecute2[T0,T1,TRet](CallSite site, T0 arg0, T1 arg1) at CallSite.Target(Closure, CallSite, Object, String) at (Closure, FunctionContext) CategoryInfo : NotSpecified: (:) [], MethodException FullyQualifiedErrorId : MethodCountCouldNotFindBest InvocationInfo : ScriptLineNumber : 136 OffsetInLine : 9 HistoryId : 1 ScriptName : C:\home\site\wwwroot\JCQueueTrigger1\run.ps1 Line : $LastRecordTimestamp = $LastRecordTimeStamp.ToString('yyyy-MM-ddThh:mm:ssZ') Statement : $LastRecordTimestamp = $LastRecordTimeStamp.ToString('yyyy-MM-ddThh:mm:ssZ') PositionMessage : At C:\home\site\wwwroot\JCQueueTrigger1\run.ps1:136 char:9 + $LastRecordTimestamp = $LastRecordTimeStamp.ToString('yyyy-MM … + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ PSScriptRoot : C:\home\site\wwwroot\JCQueueTrigger1 PSCommandPath : C:\home\site\wwwroot\JCQueueTrigger1\run.ps1 CommandOrigin : Internal ScriptStackTrace : at , C:\home\site\wwwroot\JCQueueTrigger1\run.ps1: line 136
2025-01-21T11:35:07Z [Error] ERROR: Cannot find an overload for "ToString" and the argument count: "1". Exception : Type : System.Management.Automation.MethodException ErrorRecord : Exception : Type : System.Management.Automation.ParentContainsErrorRecordException Message : Cannot find an overload for "ToString" and the argument count: "1". HResult : -2146233087 CategoryInfo : NotSpecified: (:) [], ParentContainsErrorRecordException FullyQualifiedErrorId : MethodCountCouldNotFindBest InvocationInfo : ScriptLineNumber : 136 OffsetInLine : 9 HistoryId : 1 ScriptName : C:\home\site\wwwroot\JCQueueTrigger1\run.ps1 Line : $LastRecordTimestamp = $LastRecordTimeStamp.ToString('yyyy-MM-ddThh:mm:ssZ') Statement : $LastRecordTimestamp = $LastRecordTimeStamp.ToString('yyyy-MM-ddThh:mm:ssZ') PositionMessage : At C:\home\site\wwwroot\JCQueueTrigger1\run.ps1:136 char:9 + $LastRecordTimestamp = $LastRecordTimeStamp.ToString('yyyy-MM … + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ PSScriptRoot : C:\home\site\wwwroot\JCQueueTrigger1 PSCommandPath : C:\home\site\wwwroot\JCQueueTrigger1\run.ps1 CommandOrigin : Internal ScriptStackTrace : at , C:\home\site\wwwroot\JCQueueTrigger1\run.ps1: line 136 TargetSite : System.Object CallSite.Target(System.Runtime.CompilerServices.Closure, System.Runtime.CompilerServices.CallSite, System.Object, System.String) Message : Cannot find an overload for "ToString" and the argument count: "1". Source : Anonymously Hosted DynamicMethods Assembly HResult : -2146233087 StackTrace : at CallSite.Target(Closure, CallSite, Object, String) at (Closure, FunctionContext) CategoryInfo : NotSpecified: (:) [], MethodException FullyQualifiedErrorId : MethodCountCouldNotFindBest InvocationInfo : ScriptLineNumber : 136 OffsetInLine : 9 HistoryId : 1 ScriptName : C:\home\site\wwwroot\JCQueueTrigger1\run.ps1 Line : $LastRecordTimestamp = $LastRecordTimeStamp.ToString('yyyy-MM-ddThh:mm:ssZ') Statement : $LastRecordTimestamp = $LastRecordTimeStamp.ToString('yyyy-MM-ddThh:mm:ssZ') PositionMessage : At C:\home\site\wwwroot\JCQueueTrigger1\run.ps1:136 char:9 + $LastRecordTimestamp = $LastRecordTimeStamp.ToString('yyyy-MM … + ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ PSScriptRoot : C:\home\site\wwwroot\JCQueueTrigger1 PSCommandPath : C:\home\site\wwwroot\JCQueueTrigger1\run.ps1 CommandOrigin : Internal ScriptStackTrace : at , C:\home\site\wwwroot\JCQueueTrigger1\run.ps1: line 136

We've already updated the runtime and the powershell core version to ~4 and 7.4 respectively based on the recommendation from this link -- #11535

To Reproduce

  1. Go to 'Log Streams' in the Function App and monitor for a few minutes for the errors to appear.

Expected behavior
I am expecting to not see any errors within the log streams and the functions

Screenshots

Additionally, is it possible to set the logging level of the function app triggers? We're getting high number of logs into the AppTraces table -- as I understand it, it's possible to edit the host.json file to add the a line to specify the logging level (https://learn.microsoft.com/en-us/azure/azure-functions/configure-monitoring?tabs=v2)

Hoping for your kind response, thank you!

@v-sudkharat v-sudkharat self-assigned this Jan 22, 2025
@v-sudkharat v-sudkharat added the Connector Connector specialty review needed label Jan 22, 2025
@v-sudkharat
Copy link
Contributor

Hi @JustineTheHacker, Thanks for flagging this issue, we will investigate this issue and get back to you with some updates. Thanks!

@v-sudkharat
Copy link
Contributor

Hi @JustineTheHacker,
Based on the error message you've shared; it appears that the value for$LastRecordTimestampmight not be consistent or is not in the correct format. Updated the script to handle this.
Could you please test the updated script in your Testing environment and let us know if the error still appears in the log stream? Unfortunately, we don't have the log flow in our environment, so your testing would be greatly appreciated.

Below is the updated zip link:
https://github.com/Azure/Azure-Sentinel/raw/8334b2101266782ae75b6f910a7b2deeb58d7d29/DataConnectors/JumpCloud%20Single%20Sign%20On/AzureFunctionJumpCloud/JumpCloudSSO.zip

Go to your function app, and update the above link in WEBSITE_RUN_FROM_PACKAGE:

Image

We have tested with available data and could not get any Error in a Log Stream :

Image

Thanks!

@v-sudkharat
Copy link
Contributor

@JustineTheHacker, Waiting for your response on above comment. Thanks!

@HotdogAndBaloney314
Copy link
Author

Hi @v-sudkharat ,

We have now test this -- however, we've seen a drastic reduction in the logs being feeded to Sentinel (which is strangely unusual)

@v-sudkharat
Copy link
Contributor

@JustineTheHacker, Thank you for the response. we will check for the connector behavior with the connector author.
Meantime, could you please send the logs with us -
a. Before updating the function app zip.
b. After updating function app zip.
It will help us analyze the received logs of different scenarios.
Email ID - [email protected]

we will request you, If you have already tested it in your production function app and not in a lab test environment, please update the website run from the package link to the old one, as this will help ensure no logs are missed.
Old link - https://aka.ms/sentinel-Jumpcloud-functionapp

If you are still testing in a lab environment, we recommend keeping the change in place and allowing more time to see if it reduces the logs. Additionally, please check whether you are encountering the same error in the log stream as seen in the preview.

Additionally, We would also like to request that you verify the logs in the JumpCloud console to ensure that the logs being received in Sentinel are the same.

Thanks!

@v-sudkharat
Copy link
Contributor

@JustineTheHacker, could you please verify and let us know that while deployment of the new function app in which the logs are reduced, is value for the Jump Cloud Event Types are same as previously it has?

Image

Change in event type value also may the reason for it.

@HotdogAndBaloney314
Copy link
Author

Hi @v-sudkharat,

I presume it still is. We didn't change anything aside from the WEBSITE_RUN_FROM_PACKAGE link. Unfortuantely, we won't be able to provide any logs from our end for confidentiality purposes. Would it be better to delete the old function app, and repdeloy a new one using the new package you provided?

Kind Regards

@HotdogAndBaloney314
Copy link
Author

Hi @v-sudkharat ,

I have checked the event types and we're still getting the same event types (though at a much lower rate)

Kind Regards

@v-sudkharat
Copy link
Contributor

Hi @JustineTheHacker, instead of deleting the function app, we recommend simply restarting the function app after updating the WEBSITERUNFROMPACKAGE link.

Answering to your question - we've seen a drastic reduction in the logs being feeded to Sentinel (which is strangely unusual) :

We tested the concern you shared with two different scenarios, deploying two function apps in different environments to verify if there’s any reduction in logs after updating the function app.

In our JumpCloud console we have Total 26 event count of logs:

Image

  1. Function App Deployment in Workspace 1 (No Changes):

    • We deployed the function app in our workspace without making any changes:
      Image

    a. After deployment, we monitored the Log Stream for errors but observed no errors, except for a warning message related to
    the storage account:
    Image

    b. In Sentinel workspace, we checked the log results:
    Image

    Image

  2. Function App Deployment in Workspace 2 (With WebsiteRunFromPackage Link Change):

    • We deployed the function app in Workspace 2 after changing the WebsiteRunFromPackage link:
      Image

    a. After deployment, we again monitored the Log Stream for errors and saw no errors except for the storage account warning:
    Image

    b. In Sentinel workspace, we checked the log results:
    Image

    Image

In both workspaces, we observed no reduction in the log count. The logs remained consistent.

Thanks!

@HotdogAndBaloney314
Copy link
Author

Hi @v-sudkharat ,

One thing I've noticed when using the previous script was there were a lot of logs being duplicated -- so it might be what caused the log reduction. I've seen more errors in the "AppTraces" table -- I will send it to your email for analysis.

Kind Regards

@HotdogAndBaloney314
Copy link
Author

Hi @v-sudkharat ,

I've sent the errors to your email ID [email protected]. Hoping for your response. Thank you!

Kind Regards

@v-sudkharat
Copy link
Contributor

@HotdogAndBaloney314, Received your mail, but attachment has been blocked by ORG, could you please resent or send it with imp.
Thanks!

@v-sudkharat
Copy link
Contributor

Hi @JustineTheHacker, instead of deleting the function app, we recommend simply restarting the function app after updating the WEBSITERUNFROMPACKAGE link.

Answering to your question - we've seen a drastic reduction in the logs being feeded to Sentinel (which is strangely unusual) :

We tested the concern you shared with two different scenarios, deploying two function apps in different environments to verify if there’s any reduction in logs after updating the function app.

In our JumpCloud console we have Total 26 event count of logs:

Image

  1. Function App Deployment in Workspace 1 (No Changes):

    • We deployed the function app in our workspace without making any changes:
      Image

    a. After deployment, we monitored the Log Stream for errors but observed no errors, except for a warning message related to
    the storage account:
    Image
    b. In Sentinel workspace, we checked the log results:
    Image
    Image

  2. Function App Deployment in Workspace 2 (With WebsiteRunFromPackage Link Change):

    • We deployed the function app in Workspace 2 after changing the WebsiteRunFromPackage link:
      Image

    a. After deployment, we again monitored the Log Stream for errors and saw no errors except for the storage account warning:
    Image
    b. In Sentinel workspace, we checked the log results:
    Image
    Image

In both workspaces, we observed no reduction in the log count. The logs remained consistent.

Thanks!

Hi @HotdogAndBaloney314, Did you validated the count on logs in Jumpcloud and function app Logs as mentioned above?
And waiting for your app trace mail
Thanks!

@HotdogAndBaloney314
Copy link
Author

Hi @v-sudkharat ,
I have resent the file, can you check please? And yes, the logs have went indeed down per checking.

Kind Regards,
Justine

@v-sudkharat
Copy link
Contributor

@HotdogAndBaloney314, Waiting for Timestamp values. Thanks!

@HotdogAndBaloney314
Copy link
Author

HotdogAndBaloney314 commented Feb 19, 2025 via email

@HotdogAndBaloney314
Copy link
Author

Hi,

I'm still waiting for this information from our customer. I will update you
as soon as I get it.

Kind regards

@HotdogAndBaloney314
Copy link
Author

HotdogAndBaloney314 commented Feb 21, 2025 via email

@v-sudkharat
Copy link
Contributor

Hi @HotdogAndBaloney314,
Thanks for sharing the Timestamp values.
Made the changes. Kindly update the WebsiteRunFromPackage link with the one below and restart the function app:
https://github.com/Azure/Azure-Sentinel/raw/a113a75974a130031ae3fe6d3f0799c28c029b52/DataConnectors/JumpCloud%20Single%20Sign%20On/AzureFunctionJumpCloud/JumpCloudSSO.zip

Note that the timestamp values should follow the format shared above: 2025-02-19T12:49:40.710299497Z.
If the timestamp values are in an encrypted format, the function will throw an error for those fields.

Thanks!

@v-sudkharat
Copy link
Contributor

@HotdogAndBaloney314, Did you get a chance to check on above comment?

@v-sudkharat
Copy link
Contributor

Hi @HotdogAndBaloney314, Gentle Reminder: We are waiting for your response on this issue. If you still need to keep this issue active, please respond to it in the next 2 days. If we don't receive a response by 04-03-2025 date, we will be closing this issue.
Thanks!

@HotdogAndBaloney314
Copy link
Author

HotdogAndBaloney314 commented Mar 3, 2025 via email

@v-sudkharat
Copy link
Contributor

@HotdogAndBaloney314, any update for us? waiting for response.

@HotdogAndBaloney314
Copy link
Author

HotdogAndBaloney314 commented Mar 6, 2025 via email

@v-sudkharat
Copy link
Contributor

Hi @HotdogAndBaloney314, please share the error for review via a mail? And as mentioned in NOTE : #11695 (comment)
If the timestamp values are in an encrypted format, the function will throw an error for those fields. So could you please verify timestamp values and let us know if it still in encrypted format from source (Jumpcloud)

Thanks!

@HotdogAndBaloney314
Copy link
Author

HotdogAndBaloney314 commented Mar 10, 2025 via email

@v-sudkharat
Copy link
Contributor

Hi @HotdogAndBaloney314, The attachment is not visible in GitHub, will requesting you to share it via our existing mail chain. And did you get a chance to verify the -If the timestamp values are in an encrypted format, the function will throw an error for those fields. So could you please verify timestamp values and let us know if it still in encrypted format from source (Jumpcloud)
Thanks!

@HotdogAndBaloney314
Copy link
Author

Hi @v-sudkharat ,

I have shared it in the email just now. Can you confirm please?

Kind Regards

@v-sudkharat
Copy link
Contributor

@HotdogAndBaloney314, Received.

@v-sudkharat
Copy link
Contributor

Hi @HotdogAndBaloney314,
We have reviewed the recent shared App Traces.
The raised issue:

ERROR: Cannot find an overload for "ToString" and the argument count: "1".  
Exception:  
Type: System.Management.Automation.MethodException  
ErrorRecord:  
Exception:  
Type: System.Management.Automation.ParentContainsErrorRecordException  
Message: Cannot find an overload for "ToString" and the argument count: "1".  
HResult: -2146233087  
CategoryInfo: NotSpecified: (:) [], ParentContainsErrorRecordException  

has been fixed in the updated code. We no longer see the ToString error in the shared App Trace logs.

  • Please note that the provided App Traces include all function app traces, not just the relevant ones.
  • The current traces you received indicate that the function app API could not find data in the header because no data was available from the source (JumpCloud). As a result, it returned a Bad Request and Null index array error.
  • We request you kindly check the function app error count to determine if the function app is failing:

Image

Image

Please let us know if we can close this issue.
Thanks!

@v-sudkharat
Copy link
Contributor

Hi @HotdogAndBaloney314, waiting for your response on above comment. Thanks!

@HotdogAndBaloney314
Copy link
Author

Hi @v-sudkharat ,

We are still in the process of checking the functions, I will get back to you as soon as possible once I have an update, thank you!

@v-sudkharat
Copy link
Contributor

Hi @HotdogAndBaloney314, Any update? waiting for confirmation. Thanks!

@v-sudkharat
Copy link
Contributor

Hi @HotdogAndBaloney314, Gentle Reminder: We are waiting for your response on this issue. If you still need to keep this issue active, please respond to it in the next 2 days. If we don't receive a response by 28-03-2025 date, we will be closing this issue.
Thanks!

@HotdogAndBaloney314
Copy link
Author

Hi @v-sudkharat ,

The function app is not getting any logs for several weeks now. I am checking the errors again, but it looks like the function app is not getting the logs from the JC portal.

Kind Regard,s
Justine

@HotdogAndBaloney314
Copy link
Author

Hi @v-sudkharat ,

It looks like there's an issue with the new zip package you've provided. As mentioned, we're not seeing logs after applying it. I can confirm that logs are being generated within the JC portal

Image

Kind Regards

@v-sudkharat
Copy link
Contributor

Hi @HotdogAndBaloney314,
We have re-validated the function app with shared zip file and can see the logs has been flow into the sentinel workspace without any miss:
The Shared WebsiteRunFromPackage link: https://github.com/Azure/Azure-Sentinel/raw/a113a75974a130031ae3fe6d3f0799c28c029b52/DataConnectors/JumpCloud%20Single%20Sign%20On/AzureFunctionJumpCloud/JumpCloudSSO.zip

Log's count in JumpCloud Portal:

Image

Log's count in Sentinel Workspace with 24 hr timespan:

Image

Will request you to validate your configuration once in Function app:

  1. Correct zip url has been mentioned in function app WebsiteRunFromPackage path:

Image

  1. Re-validate the correct values has been added for below variables and PowerShell version too :

Image

Image

  1. Restart the function app and validate the logs count in JC and Sentinel in defined Timespan (Ex: After restarting function app, generate few logs in JC and check the count has been match in sentinel too using below query):
JumpCloud_CL
|count 

Note: As function app is queue trigger, it may take some time to pull the logs. so, in each function app invocations it may not show the record count:

Image

After validating all above if still not getting the logs in workspace, kindly share the error invocations / exceptions with us via a mail. will validate it and if required will have a call.

Many Thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Connector Connector specialty review needed
Projects
None yet
Development

No branches or pull requests

2 participants