All Apps and Add-ons

Mimecast Add-on: Getting error and audit log is not being received.

Ayan
Loves-to-Learn

 I am seeing this error message from Mimecast TA, 

ERROR ExecProcessor - message from "python /opt/splunk/etc/apps/TA-mimecast-for-splunk/bin/mimecast_audit.py" ERRORHTTPSConnectionPool(host='us-api.mimecast.com', port=443): Max retries exceeded with url: /api/audit/get-audit-events (Caused by ReadTimeoutError("HTTPSConnectionPool(host='us-api.mimecast.com', port=443): Read timed out. (read timeout=30.0)",)) 

Did the Mimecast API change or it is something else causing this issue? Mimecast audit log is not getting received due to this issue.

Labels (3)
Tags (2)
0 Karma

thambisetty
SplunkTrust
SplunkTrust

It looks like, your connection is getting blocked by proxy.

check in your proxy logs if you are behind any proxy.

or you could check on your own laptop where everything is opened to see you are able to connect.

————————————
If this helps, give a like below.
0 Karma

Ayan
Loves-to-Learn

@thambisetty  We do not have any proxy.  There other inputs of this TA that are ingesting fine. Except this audit logs .

0 Karma

thambisetty
SplunkTrust
SplunkTrust

Its looking like connection error only Based on the error you have posted.

can you Check in internal what is the domain used for other logs ? Is that same us-api.mimiecast.com

————————————
If this helps, give a like below.
0 Karma

Ayan
Loves-to-Learn

@thambisetty Do you have any suggestions on this?

0 Karma

thambisetty
SplunkTrust
SplunkTrust

I have changed a lot this TA 1.5 years ago to make it work.

I really need to look into it to understand where the problem is.

please message me, I can look it into for you.

————————————
If this helps, give a like below.
0 Karma

Ayan
Loves-to-Learn

That's correct, the domain is us-api.mimecast.com. That's base url to use for U.S 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...