<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not receiving CrowdStrike Intel Indicators events in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Not-receiving-CrowdStrike-Intel-Indicators-events/m-p/536849#M89989</link>
    <description>&lt;P&gt;Which "CloudStrike cloud environment" do you have selected? In my case it didn't work until "EU Cloud" was selected. After switching to "US Commercial" it started working.&lt;/P&gt;&lt;P&gt;Currently using EU Cloud is not beneficiary, since all requests are (at least currently) redirected to US commercial anyway.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Jan 2021 15:51:31 GMT</pubDate>
    <dc:creator>MaverickT</dc:creator>
    <dc:date>2021-01-22T15:51:31Z</dc:date>
    <item>
      <title>Not receiving CrowdStrike Intel Indicators events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-receiving-CrowdStrike-Intel-Indicators-events/m-p/524995#M88641</link>
      <description>&lt;P&gt;Followed this &lt;A href="https://www.crowdstrike.com/wp-content/uploads/2020/07/CrowdStrike-Falcon-Intel-Indicator-Add-on-Guide.pdf" target="_self"&gt;guide&lt;/A&gt; properly but not getting any Falcon Indicator events in Splunk and getting the following message in log file&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;2020-10-16 14:37:04,341 INFO pid=488 tid=MainThread file=splunk_rest_client.py:_request_handler:105 | Use HTTP connection pooling
2020-10-16 14:37:05,289 INFO pid=488 tid=MainThread file=base_modinput.py:log_info:295 | Authentication status code: 201
2020-10-16 14:37:05,289 INFO pid=488 tid=MainThread file=base_modinput.py:log_info:295 | Successfully Retrieved Authentication Token
2020-10-16 14:37:05,563 ERROR pid=488 tid=MainThread file=base_modinput.py:log_error:309 | Get error when collecting events.
Traceback (most recent call last):
  File "/opt/splunk/etc/apps/TA-crowdstrike-intel-indicators/bin/ta_crowdstrike_intel_indicators/aob_py2/modinput_wrapper/base_modinput.py", line 128, in stream_events
    self.collect_events(ew)
  File "/opt/splunk/etc/apps/TA-crowdstrike-intel-indicators/bin/crowdstrike_intel_indicators.py", line 77, in collect_events
    input_module.collect_events(self, ew)
  File "/opt/splunk/etc/apps/TA-crowdstrike-intel-indicators/bin/input_module_crowdstrike_intel_indicators.py", line 157, in collect_events
    indicators = intel['resources']
KeyError: 'resources'&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please advise. Thanks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Oct 2020 04:14:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-receiving-CrowdStrike-Intel-Indicators-events/m-p/524995#M88641</guid>
      <dc:creator>damode</dc:creator>
      <dc:date>2020-10-16T04:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: Not receiving CrowdStrike Intel Indicators events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-receiving-CrowdStrike-Intel-Indicators-events/m-p/536849#M89989</link>
      <description>&lt;P&gt;Which "CloudStrike cloud environment" do you have selected? In my case it didn't work until "EU Cloud" was selected. After switching to "US Commercial" it started working.&lt;/P&gt;&lt;P&gt;Currently using EU Cloud is not beneficiary, since all requests are (at least currently) redirected to US commercial anyway.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Jan 2021 15:51:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-receiving-CrowdStrike-Intel-Indicators-events/m-p/536849#M89989</guid>
      <dc:creator>MaverickT</dc:creator>
      <dc:date>2021-01-22T15:51:31Z</dc:date>
    </item>
  </channel>
</rss>

