<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Windows Defender ATP - error after configuring connection in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Defender-ATP-error-after-configuring-connection/m-p/425619#M52024</link>
    <description>&lt;P&gt;Hi Chad&lt;/P&gt;

&lt;P&gt;in your debug output i can see a type. The Endpoint should be "&lt;A href="https://wdatp-alertexporter-us.securitycenter.windows.com"&gt;https://wdatp-alertexporter-us.securitycenter.windows.com&lt;/A&gt;" and not " &lt;A href="https://wdatp-alertexporter-us.securitycenter.windows.com/api/alerts"&gt;https://wdatp-alertexporter-us.securitycenter.windows.com/api/alerts&lt;/A&gt;"&lt;/P&gt;

&lt;P&gt;Best Regards&lt;BR /&gt;
Damian&lt;/P&gt;</description>
    <pubDate>Thu, 16 Apr 2020 13:36:12 GMT</pubDate>
    <dc:creator>dasmind</dc:creator>
    <dc:date>2020-04-16T13:36:12Z</dc:date>
    <item>
      <title>Windows Defender ATP - error after configuring connection</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Defender-ATP-error-after-configuring-connection/m-p/425612#M52017</link>
      <description>&lt;P&gt;Issue when configure connection string for Windows Defender ATP.&lt;/P&gt;

&lt;P&gt;Shows this in log file &lt;CODE&gt;ta_windows_defender_windows_defender_atp_alerts.log&lt;/CODE&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;2019-08-02 14:46:37,060 INFO pid=18110 tid=MainThread file=connectionpool.py:_new_conn:758 | Starting new HTTPS connection (1): 127.0.0.1
2019-08-02 14:46:38,018 INFO pid=18110 tid=MainThread file=connectionpool.py:_new_conn:758 | Starting new HTTPS connection (1): 127.0.0.1
2019-08-02 14:46:39,513 INFO pid=18110 tid=MainThread file=connectionpool.py:_new_conn:758 | Starting new HTTPS connection (1): 127.0.0.1
2019-08-02 14:46:41,071 INFO pid=18110 tid=MainThread file=connectionpool.py:_new_conn:758 | Starting new HTTPS connection (1): 127.0.0.1
2019-08-02 14:46:42,585 INFO pid=18110 tid=MainThread file=splunk_rest_client.py:_request_handler:100 | Use HTTP connection pooling
2019-08-02 14:46:42,586 INFO pid=18110 tid=MainThread file=connectionpool.py:_new_conn:758 | Starting new HTTPS connection (1): 127.0.0.1
2019-08-02 14:46:42,600 INFO pid=18110 tid=MainThread file=setup_util.py:log_info:114 | Proxy is not enabled!
2019-08-02 14:46:42,770 ERROR pid=18110 tid=MainThread file=base_modinput.py:log_error:307 | No JSON object could be decoded
2019-08-02 14:46:42,771 ERROR pid=18110 tid=MainThread file=base_modinput.py:log_error:307 | Get error when collecting events.
Traceback (most recent call last):
  File "/opt/splunk/etc/apps/TA_windows-defender/bin/ta_windows_defender/modinput_wrapper/base_modinput.py", line 127, in stream_events
    self.collect_events(ew)
  File "/opt/splunk/etc/apps/TA_windows-defender/bin/windows_defender_atp_alerts.py", line 88, in collect_events
    input_module.collect_events(self, ew)
  File "/opt/splunk/etc/apps/TA_windows-defender/bin/input_module_windows_defender_atp_alerts.py", line 151, in collect_events
    "Authorization": 'Bearer ' + access_token,
TypeError: cannot concatenate 'str' and 'NoneType' objects
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 02 Aug 2019 12:56:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Defender-ATP-error-after-configuring-connection/m-p/425612#M52017</guid>
      <dc:creator>rene_securelink</dc:creator>
      <dc:date>2019-08-02T12:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Defender ATP - error after configuring connection</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Defender-ATP-error-after-configuring-connection/m-p/425613#M52018</link>
      <description>&lt;P&gt;Did anyone ever find the answer to this issue? I'm having the same problem. &lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2019 03:12:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Defender-ATP-error-after-configuring-connection/m-p/425613#M52018</guid>
      <dc:creator>ajaynes</dc:creator>
      <dc:date>2019-09-17T03:12:28Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Defender ATP - error after configuring connection</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Defender-ATP-error-after-configuring-connection/m-p/425614#M52019</link>
      <description>&lt;P&gt;If you want to onboard Windows Defender ATP you will need to use Microsoft Graph Security API Add-On for Splunk.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/4564/#/details"&gt;https://splunkbase.splunk.com/app/4564/#/details&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Sep 2019 03:33:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Defender-ATP-error-after-configuring-connection/m-p/425614#M52019</guid>
      <dc:creator>ajaynes</dc:creator>
      <dc:date>2019-09-19T03:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Defender ATP - error after configuring connection</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Defender-ATP-error-after-configuring-connection/m-p/425615#M52020</link>
      <description>&lt;P&gt;I'm having the exact same error. However, it works on my all-in-one Splunk instance but not when moved over to my HF.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 18:57:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Defender-ATP-error-after-configuring-connection/m-p/425615#M52020</guid>
      <dc:creator>ChadLangUAB</dc:creator>
      <dc:date>2020-01-29T18:57:59Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Defender ATP - error after configuring connection</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Defender-ATP-error-after-configuring-connection/m-p/425616#M52021</link>
      <description>&lt;P&gt;Why do you think this is the answer? I could not get it to work with the same API connection used for the Windows Defender ATP Modular Inputs TA, which works on my dev instance.&lt;/P&gt;

&lt;P&gt;The guidance directly from Microsoft is to use the Windows Defender ATP Modular Inputs TA, step 1 below:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/configure-splunk"&gt;https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/configure-splunk&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2020 19:00:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Defender-ATP-error-after-configuring-connection/m-p/425616#M52021</guid>
      <dc:creator>ChadLangUAB</dc:creator>
      <dc:date>2020-01-29T19:00:13Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Defender ATP - error after configuring connection</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Defender-ATP-error-after-configuring-connection/m-p/425617#M52022</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;After about a month of trying everything and anything I randomly read this splunk doc:&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Security/HowtoprepareyoursignedcertificatesforSplunk"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Security/HowtoprepareyoursignedcertificatesforSplunk&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Replace &lt;CODE&gt;latest&lt;/CODE&gt; with Splunk version being used and read about certificate chaining:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[ server certificate]
[ intermediate certificate]
[ root certificate (if required) ]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I went here:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$SPLUNK_HOME/etc/apps/TA_windows-defender/bin/ta_windows_defender/requests/
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It turns out that &lt;CODE&gt;TA_windows_defender&lt;/CODE&gt; needed my &lt;CODE&gt;root certificate&lt;/CODE&gt; appended to the &lt;CODE&gt;cacerts.pem&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;I suggest backing your certs up, and then append with a command that works:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;cat org.pem &amp;gt;&amp;gt; cacaerts.pem 
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If it looks correct restart splunk . I hope you had the same issue and it is fixed.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;Happy Splunking!&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2020 22:21:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Defender-ATP-error-after-configuring-connection/m-p/425617#M52022</guid>
      <dc:creator>smcclory</dc:creator>
      <dc:date>2020-02-28T22:21:24Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Defender ATP - error after configuring connection</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Defender-ATP-error-after-configuring-connection/m-p/425618#M52023</link>
      <description>&lt;P&gt;Thanks for the input! I've tried catting my intermediate/root PEM to cacert.pem &amp;amp; restarted Splunk on my Windows HF and the log is:&lt;/P&gt;

&lt;P&gt;2020-03-03 14:19:50,694 INFO pid=1140 tid=MainThread file=connectionpool.py:_new_conn:758 | Starting new HTTPS connection (1): 127.0.0.1&lt;BR /&gt;
2020-03-03 14:20:06,312 INFO pid=1140 tid=MainThread file=connectionpool.py:_new_conn:758 | Starting new HTTPS connection (1): 127.0.0.1&lt;BR /&gt;
2020-03-03 14:20:16,960 INFO pid=1140 tid=MainThread file=connectionpool.py:_new_conn:758 | Starting new HTTPS connection (1): 127.0.0.1&lt;BR /&gt;
2020-03-03 14:20:27,624 INFO pid=1140 tid=MainThread file=connectionpool.py:_new_conn:758 | Starting new HTTPS connection (1): 127.0.0.1&lt;BR /&gt;
2020-03-03 14:20:36,272 DEBUG pid=1140 tid=MainThread file=base_modinput.py:log_debug:286 | Log Level is set to :DEBUG&lt;BR /&gt;
2020-03-03 14:20:36,273 DEBUG pid=1140 tid=MainThread file=base_modinput.py:log_debug:286 | Checkpoint key:UAB_obj_checkpoint&lt;BR /&gt;
2020-03-03 14:20:36,273 DEBUG pid=1140 tid=MainThread file=base_modinput.py:log_debug:286 | Login URL:&lt;A href="https://login.microsoftonline.com" target="_blank"&gt;https://login.microsoftonline.com&lt;/A&gt;&lt;BR /&gt;
2020-03-03 14:20:36,273 DEBUG pid=1140 tid=MainThread file=base_modinput.py:log_debug:286 | Endpoint : &lt;A href="https://wdatp-alertexporter-us.securitycenter.windows.com/api/alerts" target="_blank"&gt;https://wdatp-alertexporter-us.securitycenter.windows.com/api/alerts&lt;/A&gt;&lt;BR /&gt;
2020-03-03 14:20:36,273 DEBUG pid=1140 tid=MainThread file=base_modinput.py:log_debug:286 | Tenant ID:d8999fe4-76af-40b3-b435-1d8977abc08c&lt;BR /&gt;
2020-03-03 14:20:36,273 DEBUG pid=1140 tid=MainThread file=base_modinput.py:log_debug:286 | Resource:&lt;A href="https://graph.windows.net" target="_blank"&gt;https://graph.windows.net&lt;/A&gt;&lt;BR /&gt;
2020-03-03 14:20:36,273 DEBUG pid=1140 tid=MainThread file=base_modinput.py:log_debug:286 | Client ID:463e0c66-ee95-4031-b430-00ee5a6575b2&lt;BR /&gt;
2020-03-03 14:20:36,273 DEBUG pid=1140 tid=MainThread file=base_modinput.py:log_debug:286 | Start Date Input:None&lt;BR /&gt;
2020-03-03 14:20:36,273 INFO pid=1140 tid=MainThread file=splunk_rest_client.py:_request_handler:100 | Use HTTP connection pooling&lt;BR /&gt;
2020-03-03 14:20:36,273 DEBUG pid=1140 tid=MainThread file=binding.py:get:664 | GET request to &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/TA_windows-defender/storage/collections/config/TA_windows_defender_checkpointer" target="_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/TA_windows-defender/storage/collections/config/TA_windows_defender_checkpointer&lt;/A&gt; (body: {})&lt;BR /&gt;
2020-03-03 14:20:36,275 INFO pid=1140 tid=MainThread file=connectionpool.py:_new_conn:758 | Starting new HTTPS connection (1): 127.0.0.1&lt;BR /&gt;
2020-03-03 14:20:36,279 DEBUG pid=1140 tid=MainThread file=connectionpool.py:_make_request:387 | "GET /servicesNS/nobody/TA_windows-defender/storage/collections/config/TA_windows_defender_checkpointer HTTP/1.1" 200 5497&lt;BR /&gt;
2020-03-03 14:20:36,280 DEBUG pid=1140 tid=MainThread file=binding.py:new_f:71 | Operation took 0:00:00.006000&lt;BR /&gt;
2020-03-03 14:20:36,280 DEBUG pid=1140 tid=MainThread file=binding.py:get:664 | GET request to &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/TA_windows-defender/storage/collections/config/" target="_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/TA_windows-defender/storage/collections/config/&lt;/A&gt; (body: {'count': -1, 'search': 'TA_windows_defender_checkpointer', 'offset': 0})&lt;BR /&gt;
2020-03-03 14:20:36,283 DEBUG pid=1140 tid=MainThread file=connectionpool.py:_make_request:387 | "GET /servicesNS/nobody/TA_windows-defender/storage/collections/config/?count=-1&amp;amp;search=TA_windows_defender_checkpointer&amp;amp;offset=0 HTTP/1.1" 200 4685&lt;BR /&gt;
2020-03-03 14:20:36,283 DEBUG pid=1140 tid=MainThread file=binding.py:new_f:71 | Operation took 0:00:00.003000&lt;BR /&gt;
2020-03-03 14:20:36,288 DEBUG pid=1140 tid=MainThread file=binding.py:get:664 | GET request to &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/TA_windows-defender/storage/collections/data/TA_windows_defender_checkpointer/UAB_obj_checkpoint" target="_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/TA_windows-defender/storage/collections/data/TA_windows_defender_checkpointer/UAB_obj_checkpoint&lt;/A&gt; (body: {})&lt;BR /&gt;
2020-03-03 14:20:36,312 DEBUG pid=1140 tid=MainThread file=connectionpool.py:_make_request:387 | "GET /servicesNS/nobody/TA_windows-defender/storage/collections/data/TA_windows_defender_checkpointer/UAB_obj_checkpoint HTTP/1.1" 404 140&lt;BR /&gt;
2020-03-03 14:20:36,313 DEBUG pid=1140 tid=MainThread file=base_modinput.py:log_debug:286 | Max date before getting message: 2020-02-25 14:20:36.314000&lt;BR /&gt;
2020-03-03 14:20:36,313 DEBUG pid=1140 tid=MainThread file=base_modinput.py:log_debug:286 | UTC Time Now:2020-03-03 20:20:36.314000&lt;BR /&gt;
2020-03-03 14:20:36,315 DEBUG pid=1140 tid=MainThread file=binding.py:get:664 | GET request to &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/TA_windows-defender/storage/collections/data/TA_windows_defender_checkpointer/accesstoken" target="_blank"&gt;https://127.0.0.1:8089/servicesNS/nobody/TA_windows-defender/storage/collections/data/TA_windows_defender_checkpointer/accesstoken&lt;/A&gt; (body: {})&lt;BR /&gt;
2020-03-03 14:20:36,316 DEBUG pid=1140 tid=MainThread file=connectionpool.py:_make_request:387 | "GET /servicesNS/nobody/TA_windows-defender/storage/collections/data/TA_windows_defender_checkpointer/accesstoken HTTP/1.1" 404 140&lt;BR /&gt;
2020-03-03 14:20:36,318 DEBUG pid=1140 tid=MainThread file=base_modinput.py:log_debug:286 | get access token called&lt;BR /&gt;
2020-03-03 14:20:36,318 INFO pid=1140 tid=MainThread file=setup_util.py:log_info:114 | Proxy is not enabled!&lt;BR /&gt;
2020-03-03 14:20:36,318 DEBUG pid=1140 tid=MainThread file=base_modinput.py:log_debug:286 | Proxies set is : {}&lt;BR /&gt;
2020-03-03 14:20:36,318 DEBUG pid=1140 tid=MainThread file=base_modinput.py:log_debug:286 | Global SSL Verify settings is: True&lt;BR /&gt;
2020-03-03 14:20:36,342 DEBUG pid=1140 tid=MainThread file=connectionpool.py:_new_conn:809 | Starting new HTTPS connection (1): login.microsoftonline.com&lt;BR /&gt;
2020-03-03 14:20:36,671 DEBUG pid=1140 tid=MainThread file=connectionpool.py:_make_request:400 | &lt;A href="https://login.microsoftonline.com:443" target="_blank"&gt;https://login.microsoftonline.com:443&lt;/A&gt; "POST /d8999fe4-76af-40b3-b435-1d8977abc08c/oauth2/token HTTP/1.1" 401 471&lt;BR /&gt;
2020-03-03 14:20:36,676 ERROR pid=1140 tid=MainThread file=base_modinput.py:log_error:307 | 'access_token'&lt;BR /&gt;
2020-03-03 14:20:36,677 ERROR pid=1140 tid=MainThread file=base_modinput.py:log_error:307 | Get error when collecting events.&lt;BR /&gt;
Traceback (most recent call last):&lt;BR /&gt;
  File "C:\Program Files\Splunk\etc\apps\TA_windows-defender\bin\ta_windows_defender\modinput_wrapper\base_modinput.py", line 127, in stream_events&lt;BR /&gt;
    self.collect_events(ew)&lt;BR /&gt;
  File "C:\Program Files\Splunk\etc\apps\TA_windows-defender\bin\windows_defender_atp_alerts.py", line 88, in collect_events&lt;BR /&gt;
    input_module.collect_events(self, ew)&lt;BR /&gt;
  File "C:\Program Files\Splunk\etc\apps\TA_windows-defender\bin\input_module_windows_defender_atp_alerts.py", line 151, in collect_events&lt;BR /&gt;
    "Authorization": 'Bearer ' + access_token,&lt;BR /&gt;
TypeError: cannot concatenate 'str' and 'NoneType' objects&lt;/P&gt;

&lt;P&gt;Pretty frustrating. FYI had a Splunk PS guy onsite for a couple weeks and he was clueless.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:27:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Defender-ATP-error-after-configuring-connection/m-p/425618#M52023</guid>
      <dc:creator>ChadLangUAB</dc:creator>
      <dc:date>2020-09-30T04:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: Windows Defender ATP - error after configuring connection</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Defender-ATP-error-after-configuring-connection/m-p/425619#M52024</link>
      <description>&lt;P&gt;Hi Chad&lt;/P&gt;

&lt;P&gt;in your debug output i can see a type. The Endpoint should be "&lt;A href="https://wdatp-alertexporter-us.securitycenter.windows.com"&gt;https://wdatp-alertexporter-us.securitycenter.windows.com&lt;/A&gt;" and not " &lt;A href="https://wdatp-alertexporter-us.securitycenter.windows.com/api/alerts"&gt;https://wdatp-alertexporter-us.securitycenter.windows.com/api/alerts&lt;/A&gt;"&lt;/P&gt;

&lt;P&gt;Best Regards&lt;BR /&gt;
Damian&lt;/P&gt;</description>
      <pubDate>Thu, 16 Apr 2020 13:36:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Windows-Defender-ATP-error-after-configuring-connection/m-p/425619#M52024</guid>
      <dc:creator>dasmind</dc:creator>
      <dc:date>2020-04-16T13:36:12Z</dc:date>
    </item>
  </channel>
</rss>

