All Apps and Add-ons

Mimecast Add-on: Getting error and audit log is not being received.

Ayan
Loves-to-Learn

 I am seeing this error message from Mimecast TA, 

ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-mimecast-for-splunk/bin/mimecast_audit.py" ERRORHTTPSConnectionPool(host='us-api.mimecast.com', port=443): Max retries exceeded with url: /api/audit/get-audit-events (Caused by ReadTimeoutError("HTTPSConnectionPool(host='us-api.mimecast.com', port=443): Read timed out. (read timeout=30.0)",)) 

Did the Mimecast API change or it is something else causing this issue? Mimecast audit log is not getting received due to this issue.

Labels (3)
Tags (2)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

It looks like, your connection is getting blocked by proxy.

check in your proxy logs if you are behind any proxy.

or you could check on your own laptop where everything is opened to see you are able to connect.

————————————
If this helps, give a like below.
0 Karma

Ayan
Loves-to-Learn

@thambisetty  We do not have any proxy.  There other inputs of this TA that are ingesting fine. Except this audit logs .

0 Karma

thambisetty
SplunkTrust
SplunkTrust

Its looking like connection error only Based on the error you have posted.

can you Check in internal what is the domain used for other logs ? Is that same us-api.mimiecast.com

————————————
If this helps, give a like below.
0 Karma

Ayan
Loves-to-Learn

@thambisetty Do you have any suggestions on this?

0 Karma

thambisetty
SplunkTrust
SplunkTrust

I have changed a lot this TA 1.5 years ago to make it work.

I really need to look into it to understand where the problem is.

please message me, I can look it into for you.

————————————
If this helps, give a like below.
0 Karma

Ayan
Loves-to-Learn

That's correct, the domain is us-api.mimecast.com. That's base url to use for U.S 

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...