<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SentinelOne App Errors in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SentinelOne-App-Errors/m-p/747450#M82007</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm trying to get SentinelOne data into my cloud instance but I'm getting errors similar to this related to the inputs. At first I was having an issue with authentication errors using the API. I believe that's resolved after regenerating the key, because these are the only logs I can see in the index I created for S1.&lt;/P&gt;&lt;P&gt;error_message="[HTTP 404] &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/sentinelone_app_for_splunk/configs/conf-authhosts/********?output_mode=json" target="_blank" rel="noopener"&gt;https://127.0.0.1:8089/servicesNS/nobody/sentinelone_app_for_splunk/configs/conf-authhosts/********?output_mode=json&lt;/A&gt;" error_type="&amp;amp;lt;class 'splunk.ResourceNotFound'&amp;amp;gt;" error_arguments="[HTTP 404] &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/sentinelone_app_for_splunk/configs/conf-authhosts/***********?output_mode=json" target="_blank" rel="noopener"&gt;https://127.0.0.1:8089/servicesNS/nobody/sentinelone_app_for_splunk/configs/conf-authhosts/***********?output_mode=json&lt;/A&gt;" error_filename="s1_client.py" error_line_number="162" input_guid="*****************" input_name="Threats"&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 16:30:51 GMT</pubDate>
    <dc:creator>dompico</dc:creator>
    <dc:date>2025-06-04T16:30:51Z</dc:date>
    <item>
      <title>SentinelOne App Errors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SentinelOne-App-Errors/m-p/747450#M82007</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm trying to get SentinelOne data into my cloud instance but I'm getting errors similar to this related to the inputs. At first I was having an issue with authentication errors using the API. I believe that's resolved after regenerating the key, because these are the only logs I can see in the index I created for S1.&lt;/P&gt;&lt;P&gt;error_message="[HTTP 404] &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/sentinelone_app_for_splunk/configs/conf-authhosts/********?output_mode=json" target="_blank" rel="noopener"&gt;https://127.0.0.1:8089/servicesNS/nobody/sentinelone_app_for_splunk/configs/conf-authhosts/********?output_mode=json&lt;/A&gt;" error_type="&amp;amp;lt;class 'splunk.ResourceNotFound'&amp;amp;gt;" error_arguments="[HTTP 404] &lt;A href="https://127.0.0.1:8089/servicesNS/nobody/sentinelone_app_for_splunk/configs/conf-authhosts/***********?output_mode=json" target="_blank" rel="noopener"&gt;https://127.0.0.1:8089/servicesNS/nobody/sentinelone_app_for_splunk/configs/conf-authhosts/***********?output_mode=json&lt;/A&gt;" error_filename="s1_client.py" error_line_number="162" input_guid="*****************" input_name="Threats"&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 16:30:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SentinelOne-App-Errors/m-p/747450#M82007</guid>
      <dc:creator>dompico</dc:creator>
      <dc:date>2025-06-04T16:30:51Z</dc:date>
    </item>
    <item>
      <title>Re: SentinelOne App Errors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SentinelOne-App-Errors/m-p/747452#M82008</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/310647"&gt;@dompico&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I assume that this is installed on a heavy forwarder within your environment? Please can you confirm how you've installed the app? It looks like the app is looking for authhosts.conf which it cannot find.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The app doesnt ship with this file, so I presume its generated as part of the modular input when it runs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are there any other errors before this error relating to the retrieval of content from S1 that might be used to populate this conf file?&lt;/P&gt;&lt;P&gt;Theres a similar thread at&amp;nbsp;&lt;A href="https://community.splunk.com/t5/All-Apps-and-Add-ons/sentinelone-app-no-longer-able-to-connect-to-sentinelone/m-p/692354" target="_blank"&gt;https://community.splunk.com/t5/All-Apps-and-Add-ons/sentinelone-app-no-longer-able-to-connect-to-sentinelone/m-p/692354&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 06:37:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SentinelOne-App-Errors/m-p/747452#M82008</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-06-04T06:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: SentinelOne App Errors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SentinelOne-App-Errors/m-p/747471#M82009</link>
      <description>&lt;P&gt;Good Salutations!&lt;/P&gt;&lt;P&gt;That error is indicating that credentials cannot be found. It can typically happen when there are multiple SentinelOne Apps installed on the same instance (App, IA, TA).&amp;nbsp;&lt;/P&gt;&lt;P&gt;If there is more than one installed, remove the ones not for that tier (App =&amp;gt; SearchHeads, IA=&amp;gt; HF/IDM, TA=&amp;gt;IDX). These should be fully removed, "rm rf" if you will, not just disabled. Removed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once removed, re-configure the app and try again.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 14:03:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SentinelOne-App-Errors/m-p/747471#M82009</guid>
      <dc:creator>aplura_llc_supp</dc:creator>
      <dc:date>2025-06-04T14:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: SentinelOne App Errors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SentinelOne-App-Errors/m-p/747477#M82010</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I only have this one app from S1 installed on the indexer/searchhead which is in Splunk cloud.&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 15:49:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SentinelOne-App-Errors/m-p/747477#M82010</guid>
      <dc:creator>dompico</dc:creator>
      <dc:date>2025-06-04T15:49:53Z</dc:date>
    </item>
    <item>
      <title>Re: SentinelOne App Errors</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/SentinelOne-App-Errors/m-p/747479#M82011</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;This is installed directly on the splunk cloud instance. I just started using splunk about a week ago. To my knowledge, I don't have cli access to modify any files. I also don't see why I would need to, as there is no mention of a need to in the instructions. They seem to have built everything you would need into the app configuration pages such as fields to input api key and whatnot.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also found the thread you mentioned, but it seems no one was able to come up with a solution then either.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-06-04 085635.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39287iC5EA54E53D415D2F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-06-04 085635.png" alt="Screenshot 2025-06-04 085635.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 15:58:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/SentinelOne-App-Errors/m-p/747479#M82011</guid>
      <dc:creator>dompico</dc:creator>
      <dc:date>2025-06-04T15:58:42Z</dc:date>
    </item>
  </channel>
</rss>

