All Apps and Add-ons

Microsoft 365 Defender Add-on Error

pkohn117
Explorer

This app worked for about a day then started giving us this error:

11-18-2021 06:04:27.982 -0500 ERROR ExecProcessor [44632 ExecProcessor] - message from "/proj/app/splunk/bin/python3.7 /proj/app/splunk/etc/apps/TA-MS_Defender/bin/microsoft_defender_atp_alerts.py" raise ConnectionError(err, request=request)
11-18-2021 06:04:27.982 -0500 ERROR ExecProcessor [44632 ExecProcessor] - message from "/proj/app/splunk/bin/python3.7 /proj/app/splunk/etc/apps/TA-MS_Defender/bin/microsoft_defender_atp_alerts.py" requests.exceptions.ConnectionError: ('Connection aborted.', ConnectionResetError(104, 'Connection reset by peer'))
11-18-2021 06:04:28.019 -0500 ERROR ExecProcessor [44632 ExecProcessor] - message from "/proj/app/splunk/bin/python3.7 /proj/app/splunk/etc/apps/TA-MS_Defender/bin/microsoft_defender_atp_alerts.py" ERROR('Connection aborted.', ConnectionResetError(104, 'Connection reset by peer'))

 

Any ideas on what would cause this error?

Labels (1)
0 Karma

VijaySrrie
Builder

Hi @pkohn117 

Why we need this add-on? We have a requirement to ingest MCAS logs into splunk (salesforce logs flows into MCAS and those logs from MCAS to be ingested into splunk) Can I use the above add-on to achieve this?

Or should I use Syslog collectors to ingest MCAS logs into splunk?

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...