<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Optiv Threat Intel: After initial configuration, getting &amp;quot;Error while posting to url=/servicesNS/nobody/optiv_threat_intel/saved/searches/....&amp;quot; in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Optiv-Threat-Intel-After-initial-configuration-getting-quot/m-p/213658#M98834</link>
    <description>&lt;P&gt;FYI this error is still there (for me at least) in v. 3.20&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/1685iBC1C0CD9DF7A0337/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 05 Dec 2016 19:43:16 GMT</pubDate>
    <dc:creator>joni73</dc:creator>
    <dc:date>2016-12-05T19:43:16Z</dc:date>
    <item>
      <title>Optiv Threat Intel: After initial configuration, getting "Error while posting to url=/servicesNS/nobody/optiv_threat_intel/saved/searches/...."</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Optiv-Threat-Intel-After-initial-configuration-getting-quot/m-p/213653#M98829</link>
      <description>&lt;P&gt;Hello world,&lt;/P&gt;

&lt;P&gt;The initial config comes back with the message:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Encountered the following error while trying to update: In handler 'localapps': Error while posting to url=/servicesNS/nobody/optiv_threat_intel/saved/searches/Optiv%20Threat%20List%20Hit%20on%20Destination%20IP%20Email%20Alert%20-%20Index%201
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any clue what I did wrong here?&lt;/P&gt;

&lt;P&gt;Thx a lot&lt;BR /&gt;
Marcus&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2016 19:19:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Optiv-Threat-Intel-After-initial-configuration-getting-quot/m-p/213653#M98829</guid>
      <dc:creator>marcuspauli</dc:creator>
      <dc:date>2016-08-05T19:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: Optiv Threat Intel: After initial configuration, getting "Error while posting to url=/servicesNS/nobody/optiv_threat_intel/saved/searches/...."</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Optiv-Threat-Intel-After-initial-configuration-getting-quot/m-p/213654#M98830</link>
      <description>&lt;P&gt;Dev here- are you editing the saved search as admin? If this issue persists please try restarting Splunk. Otherwise you can edit the search in optiv_threat_intel/default, then copy the stanza you want and paste it into local and make your changes there.&lt;BR /&gt;
Good luck.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 10:29:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Optiv-Threat-Intel-After-initial-configuration-getting-quot/m-p/213654#M98830</guid>
      <dc:creator>derekarnold</dc:creator>
      <dc:date>2020-09-29T10:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: Optiv Threat Intel: After initial configuration, getting "Error while posting to url=/servicesNS/nobody/optiv_threat_intel/saved/searches/...."</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Optiv-Threat-Intel-After-initial-configuration-getting-quot/m-p/213655#M98831</link>
      <description>&lt;P&gt;Hi Derek,&lt;/P&gt;

&lt;P&gt;I am having the same issue, I have tried restarting Splunk and making changes in the stanza. It still takes me back to the setup page and same error every time.&lt;/P&gt;

&lt;P&gt;I have even tried installing it on a different search head. Any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Aug 2016 18:29:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Optiv-Threat-Intel-After-initial-configuration-getting-quot/m-p/213655#M98831</guid>
      <dc:creator>Makinde</dc:creator>
      <dc:date>2016-08-09T18:29:14Z</dc:date>
    </item>
    <item>
      <title>Re: Optiv Threat Intel: After initial configuration, getting "Error while posting to url=/servicesNS/nobody/optiv_threat_intel/saved/searches/...."</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Optiv-Threat-Intel-After-initial-configuration-getting-quot/m-p/213656#M98832</link>
      <description>&lt;P&gt;Hi Derek,&lt;/P&gt;

&lt;P&gt;Can you let me know what config file would be updated during the initial configuration so I can update them manually. I know the macro.conf file would be updated with the three indexes but I am not sure what file gets updated with the alert configuration in the initial configuration.&lt;/P&gt;

&lt;P&gt;Maybe I can manually update this file and get past the configuration page to actually be able to see what the app looks like.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 10 Aug 2016 15:06:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Optiv-Threat-Intel-After-initial-configuration-getting-quot/m-p/213656#M98832</guid>
      <dc:creator>Makinde</dc:creator>
      <dc:date>2016-08-10T15:06:15Z</dc:date>
    </item>
    <item>
      <title>Re: Optiv Threat Intel: After initial configuration, getting "Error while posting to url=/servicesNS/nobody/optiv_threat_intel/saved/searches/...."</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Optiv-Threat-Intel-After-initial-configuration-getting-quot/m-p/213657#M98833</link>
      <description>&lt;P&gt;Update macros.con with your index names in local:&lt;BR /&gt;
Example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[network_index_one]
disabled = 0
definition = index=pan_logs
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Create app.conf in local:&lt;BR /&gt;
Example&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[default]

[install]
is_configured = 1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Create savedsearches.conf in local:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[Optiv Threat List Hit on Destination IP Email Alert - Index 1]
disabled = 0
action.email.to = my_new_security_team@example.com
cron_schedule = 35 2,14 * * *
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 10 Aug 2016 19:09:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Optiv-Threat-Intel-After-initial-configuration-getting-quot/m-p/213657#M98833</guid>
      <dc:creator>derekarnold</dc:creator>
      <dc:date>2016-08-10T19:09:25Z</dc:date>
    </item>
    <item>
      <title>Re: Optiv Threat Intel: After initial configuration, getting "Error while posting to url=/servicesNS/nobody/optiv_threat_intel/saved/searches/...."</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Optiv-Threat-Intel-After-initial-configuration-getting-quot/m-p/213658#M98834</link>
      <description>&lt;P&gt;FYI this error is still there (for me at least) in v. 3.20&lt;BR /&gt;
&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/1685iBC1C0CD9DF7A0337/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Dec 2016 19:43:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Optiv-Threat-Intel-After-initial-configuration-getting-quot/m-p/213658#M98834</guid>
      <dc:creator>joni73</dc:creator>
      <dc:date>2016-12-05T19:43:16Z</dc:date>
    </item>
  </channel>
</rss>

