<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: External handler failed with code '1' and output: 'REST ERROR[400]: Bad Request - Failed to fetch the certificate from server'. See splunkd.log for stderr output. in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/443546#M54574</link>
    <description>&lt;P&gt;This resolved the issue.&lt;/P&gt;</description>
    <pubDate>Fri, 06 Dec 2019 17:01:13 GMT</pubDate>
    <dc:creator>sylax</dc:creator>
    <dc:date>2019-12-06T17:01:13Z</dc:date>
    <item>
      <title>External handler failed with code '1' and output: 'REST ERROR[400]: Bad Request - Failed to fetch the certificate from server'. See splunkd.log for stderr output.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/443541#M54569</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;I'm configure an OPSEC LEA object on Splunk and I see the following error:&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/6710i8B6058C6AB939B18/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;How can I solve it? The IP addresses are from the CheckPoint manager.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 14:37:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/443541#M54569</guid>
      <dc:creator>sebastiandelrea</dc:creator>
      <dc:date>2019-03-18T14:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: External handler failed with code '1' and output: 'REST ERROR[400]: Bad Request - Failed to fetch the certificate from server'. See splunkd.log for stderr output.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/443542#M54570</link>
      <description>&lt;P&gt;I am seeing the same error. No solution yet ?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2019 08:49:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/443542#M54570</guid>
      <dc:creator>junedec21</dc:creator>
      <dc:date>2019-03-27T08:49:24Z</dc:date>
    </item>
    <item>
      <title>Re: External handler failed with code '1' and output: 'REST ERROR[400]: Bad Request - Failed to fetch the certificate from server'. See splunkd.log for stderr output.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/443543#M54571</link>
      <description>&lt;P&gt;@sebastiandelreal   Were you able to resolve it?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Mar 2019 09:02:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/443543#M54571</guid>
      <dc:creator>junedec21</dc:creator>
      <dc:date>2019-03-27T09:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: External handler failed with code '1' and output: 'REST ERROR[400]: Bad Request - Failed to fetch the certificate from server'. See splunkd.log for stderr output.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/443544#M54572</link>
      <description>&lt;P&gt;@sebastiandelreal This issue will occur when you will not be having the port 18210 open on your Checkpoint server.&lt;BR /&gt;
Kindly verify if the port 18210 is reachable from your Splunk instance&lt;/P&gt;

&lt;P&gt;To verify the port reachability, you can use the &lt;EM&gt;telnet&lt;/EM&gt; command from your Splunk instance.&lt;/P&gt;

&lt;P&gt;FYI - @junedec21 &lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2019 07:34:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/443544#M54572</guid>
      <dc:creator>kpanchal_splunk</dc:creator>
      <dc:date>2019-09-18T07:34:08Z</dc:date>
    </item>
    <item>
      <title>Re: External handler failed with code '1' and output: 'REST ERROR[400]: Bad Request - Failed to fetch the certificate from server'. See splunkd.log for stderr output.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/443545#M54573</link>
      <description>&lt;P&gt;I was having this same issue but believe I've found a fix to it.  I'm assuming you're running on a Linux OS as from what I understand this app won't run on a Windows server due to the application dependencies.&lt;/P&gt;

&lt;P&gt;Searching this error results in a lot of people suggesting to install the 32 bit glibc and pam libraries which I did but I still kept getting the error.  This initial portion of the configuration is just establishing the communication and pulling a certificate from your management server and is done so through a python script located at:&lt;BR /&gt;
&lt;CODE&gt;/opt/splunk/bin/etc/apps/Splunk_TA_checkpoint-opseclea/bin/./pull-cert.sh&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;When I tried to manually run that script I received the following error:&lt;BR /&gt;
&lt;CODE&gt;[root@splunkserver bin]# ./pull-cert.sh&lt;/CODE&gt;&lt;BR /&gt;
&lt;CODE&gt;./opsec-tools/opsec_pull_cert: error while loading shared libraries: libnsl.so.1: cannot open shared object file: No such file or directory&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;I installed libnsl.i686 and afterwards was able to run the script.  I then tried to run the application via the GUI and was able to successfully establish the connection/pull the cert.&lt;/P&gt;

&lt;P&gt;I'm using CentOS so my fix was: &lt;CODE&gt;sudo yum install glibc.i686 pam.i686 libnsl.i686&lt;/CODE&gt; but obviously if you're on something like Ubuntu/Debian you'd do &lt;CODE&gt;sudo apt install glibc.i686 pam.i686 libnsl.i686&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 13:31:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/443545#M54573</guid>
      <dc:creator>edavisj</dc:creator>
      <dc:date>2019-11-13T13:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: External handler failed with code '1' and output: 'REST ERROR[400]: Bad Request - Failed to fetch the certificate from server'. See splunkd.log for stderr output.</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/443546#M54574</link>
      <description>&lt;P&gt;This resolved the issue.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Dec 2019 17:01:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/443546#M54574</guid>
      <dc:creator>sylax</dc:creator>
      <dc:date>2019-12-06T17:01:13Z</dc:date>
    </item>
    <item>
      <title>Re: External handler failed with code '1' and output: 'REST ERROR[400]: Bad Request - Failed to fetch the certificate fr</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/505960#M62209</link>
      <description>&lt;P&gt;New connections fail with "REST API ERROR 400" or "Fatal error: glibc detected an invalid stdio handle" on Linux with a glibc version higher than 2.17-196&lt;BR /&gt;&lt;BR /&gt;Workaround:&lt;BR /&gt;1. Download file at&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal/user/anon/page/default.psml/media-type/html?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=50832" target="_blank" rel="noopener"&gt;https://supportcenter.checkpoint.com/supportcenter/portal/user/anon/page/default.psml/media-type/html?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=50832&lt;/A&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;replace $SPLUNK_HOME/etc/apps/Splunk_TA_checkpoint-opseclea/bin/opsec-tools binaries with the updated versions.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;3. After you update the two binaries, you must reset the one time password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;=&amp;gt; This worked for me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jun 2020 13:21:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/505960#M62209</guid>
      <dc:creator>splunkreal</dc:creator>
      <dc:date>2020-06-24T13:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: External handler failed with code '1' and output: 'REST ERROR[400]: Bad Request - Failed to fetch the certificate fr</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/517590#M63298</link>
      <description>You are the MAN! Thank you!</description>
      <pubDate>Wed, 02 Sep 2020 21:13:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/517590#M63298</guid>
      <dc:creator>_smp_</dc:creator>
      <dc:date>2020-09-02T21:13:39Z</dc:date>
    </item>
    <item>
      <title>Re: External handler failed with code '1' and output: 'REST ERROR[400]: Bad Request - Failed to fetch the certificate fr</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/520939#M63546</link>
      <description>&lt;P&gt;I've had the same problem and I updated the add-on with this patch from Checkpoint. You could try this &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/174156"&gt;@junedec21&lt;/a&gt; .&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;https://supportcenter.checkpoint.com/supportcenter/portal/user/anon/page/default.psml/media-type/html?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=50832&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 22 Sep 2020 21:48:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/520939#M63546</guid>
      <dc:creator>rafamss</dc:creator>
      <dc:date>2020-09-22T21:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: External handler failed with code '1' and output: 'REST ERROR[400]: Bad Request - Failed to fetch the certificate fr</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/564306#M74983</link>
      <description>&lt;P&gt;I had the same issue and coudn't fix it by following the guidelines above and updating the&amp;nbsp;&lt;SPAN&gt;binaries in:&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN&gt;$SPLUNK_HOME/etc/apps/Splunk_TA_checkpoint-opseclea/bin/opsec-tools&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I fixed it this way:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;1. I saw that the new SIC certificate was PULLED SUCCESSFULLY from the CheckPoint server regardless the error message "&lt;SPAN&gt;External handler failed with code '1' and output: 'REST ERROR[400]: Bad Request..."&lt;BR /&gt;The certificate was available in "&lt;STRONG&gt;$SPLUNK_HOME/etc/apps/Splunk_TA_checkpoint-opseclea/certs&lt;/STRONG&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;2. I manually editted the&amp;nbsp;&lt;FONT color="#0000FF"&gt;&lt;STRONG&gt;opseclea_connection.conf&lt;/STRONG&gt;&lt;/FONT&gt; in "&lt;STRONG&gt;$SPLUNK_HOME&lt;/STRONG&gt;&lt;STRONG&gt;/etc/apps/Splunk_TA_checkpoint-opseclea/local&lt;/STRONG&gt;" and added the new certificate under the problematic connection stanza:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;&lt;FONT color="#800000"&gt;&lt;STRONG&gt;[connection_stanza_name]&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;cert_name = &lt;STRONG&gt;connection_1234567890.p12 &lt;FONT color="#339966"&gt;&amp;lt;-- Put the name of the new certificate here&lt;/FONT&gt;&lt;/STRONG&gt;&lt;BR /&gt;fw_version = R80&lt;BR /&gt;lea_app_name = Splunk_Server_LEA&lt;BR /&gt;lea_server_auth_port = 18184&lt;BR /&gt;lea_server_auth_type = sslca&lt;BR /&gt;lea_server_ip = 10.10.10.10&lt;BR /&gt;lea_server_type = primary&lt;BR /&gt;management_server_ip = 10.10.10.11&lt;BR /&gt;opsec_entity_sic_name = CN=***,O=***&lt;BR /&gt;opsec_sic_name = CN=Splunk_Server_LEA,O=***&lt;BR /&gt;disabled = 0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;No need to restart splunkd! The connection started working right away. No error messages anymore.&lt;/P&gt;&lt;P&gt;I hope it helps colleagues who had the same issue.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 11:45:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/External-handler-failed-with-code-1-and-output-REST-ERROR-400/m-p/564306#M74983</guid>
      <dc:creator>boyanmilushev</dc:creator>
      <dc:date>2021-08-23T11:45:05Z</dc:date>
    </item>
  </channel>
</rss>

