<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cortex XDR Add-On installation in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cortex-XDR-Add-On-installation/m-p/620474#M77952</link>
    <description>&lt;P&gt;Hello all,&lt;BR /&gt;I'm trying to install Palo Alto Add-On to integrate Cortex XDR on Splunk. I followed the steps in&amp;nbsp;&lt;A href="https://splunk.paloaltonetworks.com/cortex-xdr.html" target="_blank" rel="noopener"&gt;https://splunk.paloaltonetworks.com/cortex-xdr.html&lt;/A&gt;&lt;BR /&gt;configured Tenant Name, API Key ID and API Key but when tries to retrieve events this error it's logged:&lt;BR /&gt;&lt;BR /&gt;File "/opt/splunk/etc/apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/aob_py3/requests/adapters.py", line 516, in send&lt;BR /&gt;raise ConnectionError(e, request=request)&lt;BR /&gt;requests.exceptions.ConnectionError: HTTPSConnectionPool(host='api-https', port=443): Max retries exceeded with url: //&lt;STRIKE&gt;masked_tenant_name&lt;/STRIKE&gt;.xdr.&lt;STRIKE&gt;masked_tenant_region&lt;/STRIKE&gt;.paloaltonetworks.com/.xdr.&lt;STRIKE&gt;masked_tenant_region&lt;/STRIKE&gt;.paloaltonetworks.com/public_api/v1/incidents/get_incidents/ (Caused by NewConnectionError('&amp;lt;urllib3.connection.VerifiedHTTPSConnection object at 0x7f1afcb645d0&amp;gt;: Failed to establish a new connection: [Errno -2] Name or service not known'))&lt;BR /&gt;&lt;BR /&gt;As you can see, after the message "Max retries exceeded with url:" the URL doesn't contain "https:", well this cannot be the problem.&lt;BR /&gt;The configuration it's this:&lt;BR /&gt;Name = DEV_XDR&lt;BR /&gt;Interval = 60&lt;BR /&gt;Index = default&lt;BR /&gt;Status = false&lt;BR /&gt;Tenant Namehttps://&lt;STRIKE&gt;masked_tenant_name&lt;/STRIKE&gt;.xdr.&lt;STRIKE&gt;masked_tenant_region&lt;/STRIKE&gt;.paloaltonetworks.com/&lt;BR /&gt;Tenant Region = &lt;STRIKE&gt;masked_tenant_region&lt;BR /&gt;&lt;/STRIKE&gt;API Key ID********&lt;BR /&gt;API Key********&lt;BR /&gt;&lt;BR /&gt;I tried "curl" from server with add-on to the tenant URL, and the URL can be reached&lt;BR /&gt;&lt;BR /&gt;Before openning a case in Palo Alto, did anyone had this problem or similar before?&lt;/P&gt;</description>
    <pubDate>Fri, 11 Nov 2022 08:32:35 GMT</pubDate>
    <dc:creator>rivars</dc:creator>
    <dc:date>2022-11-11T08:32:35Z</dc:date>
    <item>
      <title>Cortex XDR Add-On installation</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cortex-XDR-Add-On-installation/m-p/620474#M77952</link>
      <description>&lt;P&gt;Hello all,&lt;BR /&gt;I'm trying to install Palo Alto Add-On to integrate Cortex XDR on Splunk. I followed the steps in&amp;nbsp;&lt;A href="https://splunk.paloaltonetworks.com/cortex-xdr.html" target="_blank" rel="noopener"&gt;https://splunk.paloaltonetworks.com/cortex-xdr.html&lt;/A&gt;&lt;BR /&gt;configured Tenant Name, API Key ID and API Key but when tries to retrieve events this error it's logged:&lt;BR /&gt;&lt;BR /&gt;File "/opt/splunk/etc/apps/Splunk_TA_paloalto/bin/splunk_ta_paloalto/aob_py3/requests/adapters.py", line 516, in send&lt;BR /&gt;raise ConnectionError(e, request=request)&lt;BR /&gt;requests.exceptions.ConnectionError: HTTPSConnectionPool(host='api-https', port=443): Max retries exceeded with url: //&lt;STRIKE&gt;masked_tenant_name&lt;/STRIKE&gt;.xdr.&lt;STRIKE&gt;masked_tenant_region&lt;/STRIKE&gt;.paloaltonetworks.com/.xdr.&lt;STRIKE&gt;masked_tenant_region&lt;/STRIKE&gt;.paloaltonetworks.com/public_api/v1/incidents/get_incidents/ (Caused by NewConnectionError('&amp;lt;urllib3.connection.VerifiedHTTPSConnection object at 0x7f1afcb645d0&amp;gt;: Failed to establish a new connection: [Errno -2] Name or service not known'))&lt;BR /&gt;&lt;BR /&gt;As you can see, after the message "Max retries exceeded with url:" the URL doesn't contain "https:", well this cannot be the problem.&lt;BR /&gt;The configuration it's this:&lt;BR /&gt;Name = DEV_XDR&lt;BR /&gt;Interval = 60&lt;BR /&gt;Index = default&lt;BR /&gt;Status = false&lt;BR /&gt;Tenant Namehttps://&lt;STRIKE&gt;masked_tenant_name&lt;/STRIKE&gt;.xdr.&lt;STRIKE&gt;masked_tenant_region&lt;/STRIKE&gt;.paloaltonetworks.com/&lt;BR /&gt;Tenant Region = &lt;STRIKE&gt;masked_tenant_region&lt;BR /&gt;&lt;/STRIKE&gt;API Key ID********&lt;BR /&gt;API Key********&lt;BR /&gt;&lt;BR /&gt;I tried "curl" from server with add-on to the tenant URL, and the URL can be reached&lt;BR /&gt;&lt;BR /&gt;Before openning a case in Palo Alto, did anyone had this problem or similar before?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Nov 2022 08:32:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cortex-XDR-Add-On-installation/m-p/620474#M77952</guid>
      <dc:creator>rivars</dc:creator>
      <dc:date>2022-11-11T08:32:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Add-On installation</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cortex-XDR-Add-On-installation/m-p/620552#M77955</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;I was able to solve this problem. In the "tenant name" filed when configuring, I added the full URL, not only the tenant name. That's the reason of duplicate URL in log.&lt;BR /&gt;I configured just tenant name and now it's working fine.&lt;BR /&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 11 Nov 2022 08:31:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cortex-XDR-Add-On-installation/m-p/620552#M77955</guid>
      <dc:creator>rivars</dc:creator>
      <dc:date>2022-11-11T08:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR Add-On installation</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cortex-XDR-Add-On-installation/m-p/670261#M80003</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/249000"&gt;@rivars&lt;/a&gt;&amp;nbsp; You are a lifesaver! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 07:26:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Cortex-XDR-Add-On-installation/m-p/670261#M80003</guid>
      <dc:creator>Rakzskull</dc:creator>
      <dc:date>2023-11-30T07:26:17Z</dc:date>
    </item>
  </channel>
</rss>

