<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Futur update of this TA to work with OAuth2-based in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Future-update-of-this-TA-to-work-with-OAuth2-based/m-p/491116#M60464</link>
    <description>&lt;P&gt;Any update on this?&lt;/P&gt;</description>
    <pubDate>Wed, 27 May 2020 16:42:13 GMT</pubDate>
    <dc:creator>javanzato</dc:creator>
    <dc:date>2020-05-27T16:42:13Z</dc:date>
    <item>
      <title>Future update of this TA to work with OAuth2-based</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Future-update-of-this-TA-to-work-with-OAuth2-based/m-p/491114#M60462</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;This TA is using only the deprecated legacy key-based APIs access&lt;BR /&gt;Based on your last CS communication, the end date for this kind of access is the October 29th, 2020&lt;BR /&gt;Are you planning to update this TA accordingly or it is going to be abandoned and removed from splunkbase ?&lt;/P&gt;
&lt;P&gt;Thank you for your support&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jun 2020 18:34:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Future-update-of-this-TA-to-work-with-OAuth2-based/m-p/491114#M60462</guid>
      <dc:creator>FloSwiip</dc:creator>
      <dc:date>2020-06-06T18:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Futur update of this TA to work with OAuth2-based</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Future-update-of-this-TA-to-work-with-OAuth2-based/m-p/491115#M60463</link>
      <description>&lt;P&gt;There will be a OAuth2 version very soon.  It's currently being tested.&lt;/P&gt;</description>
      <pubDate>Fri, 08 May 2020 15:24:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Future-update-of-this-TA-to-work-with-OAuth2-based/m-p/491115#M60463</guid>
      <dc:creator>knobster</dc:creator>
      <dc:date>2020-05-08T15:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: Futur update of this TA to work with OAuth2-based</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Future-update-of-this-TA-to-work-with-OAuth2-based/m-p/491116#M60464</link>
      <description>&lt;P&gt;Any update on this?&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 16:42:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Future-update-of-this-TA-to-work-with-OAuth2-based/m-p/491116#M60464</guid>
      <dc:creator>javanzato</dc:creator>
      <dc:date>2020-05-27T16:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Futur update of this TA to work with OAuth2-based</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Future-update-of-this-TA-to-work-with-OAuth2-based/m-p/491117#M60465</link>
      <description>&lt;P&gt;Any update on new CrowdStrike Supports OAuth2 based authentications.?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 10:48:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Future-update-of-this-TA-to-work-with-OAuth2-based/m-p/491117#M60465</guid>
      <dc:creator>dileep_ey</dc:creator>
      <dc:date>2020-06-03T10:48:51Z</dc:date>
    </item>
    <item>
      <title>Re: Futur update of this TA to work with OAuth2-based</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Future-update-of-this-TA-to-work-with-OAuth2-based/m-p/491118#M60466</link>
      <description>&lt;P&gt;Nothing yet.  The team is testing it currently but should be released in late July.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 14:17:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Future-update-of-this-TA-to-work-with-OAuth2-based/m-p/491118#M60466</guid>
      <dc:creator>knobster</dc:creator>
      <dc:date>2020-06-03T14:17:03Z</dc:date>
    </item>
    <item>
      <title>Re: Futur update of this TA to work with OAuth2-based</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Future-update-of-this-TA-to-work-with-OAuth2-based/m-p/491119#M60467</link>
      <description>&lt;P&gt;Will the new version support Splunk 7.2/7.3?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jun 2020 18:00:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Future-update-of-this-TA-to-work-with-OAuth2-based/m-p/491119#M60467</guid>
      <dc:creator>javanzato</dc:creator>
      <dc:date>2020-06-03T18:00:42Z</dc:date>
    </item>
    <item>
      <title>Re: Future update of this TA to work with OAuth2-based</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Future-update-of-this-TA-to-work-with-OAuth2-based/m-p/506096#M62230</link>
      <description>&lt;P&gt;A see a&amp;nbsp;&lt;STRONG&gt;CrowdStrike Falcon Event Streams Technical Add-On&amp;nbsp;&lt;/STRONG&gt;has just been released with oAuth support and is the replacement for&amp;nbsp;&lt;STRONG&gt;CrowdStrike Falcon Endpoint Add-on.&amp;nbsp;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://splunkbase.splunk.com/app/5082/#/overview" target="_blank"&gt;https://splunkbase.splunk.com/app/5082/#/overview&lt;/A&gt;&lt;/P&gt;&lt;P&gt;However, it states only version 8 compatibility at the moment, which I hope is just due to the fact they have not tested against older versions yet.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jun 2020 06:04:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Future-update-of-this-TA-to-work-with-OAuth2-based/m-p/506096#M62230</guid>
      <dc:creator>yeahnah</dc:creator>
      <dc:date>2020-06-25T06:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: Future update of this TA to work with OAuth2-based</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Future-update-of-this-TA-to-work-with-OAuth2-based/m-p/509096#M62467</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Yes same remark about the splunk 8+ only&lt;/P&gt;&lt;P&gt;I just tried it on a splunk heavy forwarder running version 7.3.6 and I am getting the following error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;2020-07-14 16:17:48,687 ERROR pid=22745 tid=MainThread file=base_modinput.py:log_error:309 | Get error when collecting events.
Traceback (most recent call last):
  File "/opt/splunk/etc/apps/TA-crowdstrike-falcon-event-streams/bin/ta_crowdstrike_falcon_event_streams/aob_py2/modinput_wrapper/base_modinput.py", line 128, in stream_events
    self.collect_events(ew)
  File "/opt/splunk/etc/apps/TA-crowdstrike-falcon-event-streams/bin/crowdstrike_event_streams.py", line 72, in collect_events
    input_module.collect_events(self, ew)
  File "/opt/splunk/etc/apps/TA-crowdstrike-falcon-event-streams/bin/input_module_crowdstrike_event_streams.py", line 321, in collect_events
    crowdstrike_client()
  File "/opt/splunk/etc/apps/TA-crowdstrike-falcon-event-streams/bin/input_module_crowdstrike_event_streams.py", line 189, in crowdstrike_client
    token_result, token_message, token_url= Stream().get_token(clientid, secret, api_endpoint, proxy)
TypeError: 'NoneType' object is not iterable&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRIKE&gt;&lt;STRONG&gt;Edit&lt;/STRONG&gt;: I have the same failure with splunk 8.0.4.1and the default setting of python in the server.conf&lt;/STRIKE&gt;&lt;BR /&gt;&lt;STRIKE&gt;python.version = python2 &lt;/STRIKE&gt;&lt;span class="lia-unicode-emoji" title=":thinking_face:"&gt;🤔&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRIKE&gt;&lt;STRONG&gt;Edit2&lt;/STRONG&gt;: Still the same error with&lt;/STRIKE&gt;&lt;BR /&gt;&lt;STRIKE&gt;python.version = python3 &lt;/STRIKE&gt;&lt;span class="lia-unicode-emoji" title=":downcast_face_with_sweat:"&gt;😓&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Edit3&lt;/STRONG&gt;: Ok I have regenerated my api credential and it was the reason of the error ( really bad catch )&lt;BR /&gt;Now it is spamming an offset errors but maybe it is normal&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2020-07-15 07:46:14,342 INFO pid=15876 tid=Thread-1 file=base_modinput.py:log_info:295 | Event Written
2020-07-15 07:46:14,342 ERROR pid=15876 tid=Thread-1 file=Stream_Attributes.py:record_offsets:116 | Failed to record offsets to offsets file.
2020-07-15 07:46:14,376 INFO pid=15876 tid=Thread-1 file=base_modinput.py:log_info:295 | Offset recording to KV store: XXXX_Detections_feed_num_0 {u'https://firehose.crowdstrike.com/sensors/entities/datafeed/v1/0?appId=splunk_qualif': XXXXX}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Edit4&lt;/STRONG&gt;:&lt;BR /&gt;For the error in edit3, it is the creation of an empty dir in TA-crowdstrike-falcon-event-streams/bin/offsets that is missing, so python is failing to manage files here.&lt;BR /&gt;Note that is app is deployed, it is important to add it to the exclusion to not loose its contain&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2020 08:21:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Future-update-of-this-TA-to-work-with-OAuth2-based/m-p/509096#M62467</guid>
      <dc:creator>FloSwiip</dc:creator>
      <dc:date>2020-07-17T08:21:49Z</dc:date>
    </item>
  </channel>
</rss>

