<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CrowdStrike Add-on stops with Error in Security</title>
    <link>https://community.splunk.com/t5/Security/CrowdStrike-Add-on-stops-with-Error/m-p/583945#M15880</link>
    <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/205389"&gt;@guarisma&lt;/a&gt;&amp;nbsp;! How do you resolve this issue?&lt;/P&gt;</description>
    <pubDate>Mon, 07 Feb 2022 13:56:33 GMT</pubDate>
    <dc:creator>DmitriyGolovnya</dc:creator>
    <dc:date>2022-02-07T13:56:33Z</dc:date>
    <item>
      <title>CrowdStrike Add-on stops with Error</title>
      <link>https://community.splunk.com/t5/Security/CrowdStrike-Add-on-stops-with-Error/m-p/550130#M12212</link>
      <description>&lt;P&gt;Our CrowdStrike Add-on stopped pulling logs via the API giving this error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2021-05-01 19:03:31,879 ERROR pid=31672 tid=MainThread file=base_modinput.py:log_error:309 | Get error when collecting events.
Traceback (most recent call last):
  File "/opt/splunk/etc/apps/TA-crowdstrike-falcon-event-streams/bin/ta_crowdstrike_falcon_event_streams/aob_py2/modinput_wrapper/base_modinput.py", line 128, in stream_events
    self.collect_events(ew)
  File "/opt/splunk/etc/apps/TA-crowdstrike-falcon-event-streams/bin/crowdstrike_event_streams.py", line 71, in collect_events
    input_module.collect_events(self, ew)
  File "/opt/splunk/etc/apps/TA-crowdstrike-falcon-event-streams/bin/input_module_crowdstrike_event_streams.py", line 358, in collect_events
    crowdstrike_client()
  File "/opt/splunk/etc/apps/TA-crowdstrike-falcon-event-streams/bin/input_module_crowdstrike_event_streams.py", line 234, in crowdstrike_client
    num_feeds = len(response['resources'])
TypeError: object of type 'NoneType' has no len()&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't understand what happened or how to prevent it for happening again.&lt;/P&gt;&lt;P&gt;Anyone out there with same issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 02 May 2021 02:12:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/CrowdStrike-Add-on-stops-with-Error/m-p/550130#M12212</guid>
      <dc:creator>guarisma</dc:creator>
      <dc:date>2021-05-02T02:12:48Z</dc:date>
    </item>
    <item>
      <title>Re: CrowdStrike Add-on stops with Error</title>
      <link>https://community.splunk.com/t5/Security/CrowdStrike-Add-on-stops-with-Error/m-p/583945#M15880</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/205389"&gt;@guarisma&lt;/a&gt;&amp;nbsp;! How do you resolve this issue?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Feb 2022 13:56:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/CrowdStrike-Add-on-stops-with-Error/m-p/583945#M15880</guid>
      <dc:creator>DmitriyGolovnya</dc:creator>
      <dc:date>2022-02-07T13:56:33Z</dc:date>
    </item>
    <item>
      <title>Re: CrowdStrike Add-on stops with Error</title>
      <link>https://community.splunk.com/t5/Security/CrowdStrike-Add-on-stops-with-Error/m-p/584123#M15884</link>
      <description>&lt;P&gt;No, never got an answer, but we're not using CrowdStrike anymore&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Crowdstrike-Stream-Stops-Woking/m-p/536216" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Crowdstrike-Stream-Stops-Woking/m-p/536216&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 08 Feb 2022 14:54:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/CrowdStrike-Add-on-stops-with-Error/m-p/584123#M15884</guid>
      <dc:creator>guarisma</dc:creator>
      <dc:date>2022-02-08T14:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: CrowdStrike Add-on stops with Error</title>
      <link>https://community.splunk.com/t5/Security/CrowdStrike-Add-on-stops-with-Error/m-p/596427#M16076</link>
      <description>&lt;P&gt;Here's a possible explanation for the interruption some folks are seeing.&lt;/P&gt;&lt;P&gt;We observed the same behavior today with our on-prem Splunk heavy-forwarder not getting events from the &lt;SPAN&gt;CrowdStrike Falcon Event Streams API&amp;nbsp;&lt;/SPAN&gt;for the past 7 days.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We eventually found that the past 7 days of "missing" events were getting pulled into our Splunk Cloud stack where we also had deployed&amp;nbsp;&lt;SPAN&gt;CrowdStrike Falcon Event Streams add-on for Splunk.&amp;nbsp; i.e., we had 2 separate Splunk deployments requesting the same data.&amp;nbsp; It seems that only one API "client" instance would always get the data, and the other left out to dry.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;When we disabled the input configured on Splunk Cloud, the Splunk on-prem HF started to get the event stream again, collecting all 7 days of "missing" events as well as new events.&lt;/P&gt;&lt;P&gt;To enable dual inputs, we plan to configure a separate CrowdStrike API key for the Splunk Cloud stack.&lt;/P&gt;&lt;P&gt;I hope this helps others who've seen this issue.&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2022 20:47:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/CrowdStrike-Add-on-stops-with-Error/m-p/596427#M16076</guid>
      <dc:creator>staten</dc:creator>
      <dc:date>2022-05-04T20:47:18Z</dc:date>
    </item>
  </channel>
</rss>

