All Apps and Add-ons

Carbon Black Defense add-on api URL now depreciated by Carbon Black?

sirpatrick
Explorer

It would appear that at 03:15 UTC or so on 12/20/2019 calls to the integrations/v3 API started returning an error 503 for us. We had heard that they were planning to depreciate the v3 API's, but the app still uses them.

Is anyone else encountering this issue? If so, do you have a work around?

Thanks!

0 Karma

sirpatrick
Explorer

I received this information regarding the API's directly from Carbon Black while they were working on a related issue. The current add-on we are all using which is available from Splunkbase leverages API v3. I do not know the differences between v3 & v6 but would be surprised if the parsing of data would not be impacted.

Direct quote from Carbon Black:
"However, it does appear that the v3 API is considered "deprecated" and the v6 API should be used, so that is something that we should take into consideration for the future and start moving the current API integrations over to the supported version when possible. Please let me know if you have any additional concerns about this."

I guess my next step is to chase down who is responsible for items published by the "Carbon Black Developer Network" and see if this is going to be updated or allowed to die on the vine.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...