All Apps and Add-ons

Resolving Error when using VirusTotal TA?

jhilton90
Path Finder

I have installed and setup the VirusTotal TA with basic configuration i.e. API key and Max Batch Size just to test things.

However when I try to run the following command

 

index=advanced_hunting category="AdvancedHunting-UrlClickEvents" properties.UrlChain=*
| virustotal domain=properties.UrlChain

 

I get the following error

 

Error in 'virustotal' command: External search command exited unexpectedly with non-zero error code 1.

Streamed search execute failed because: Error in 'virustotal' command: External search command exited unexpectedly with non-zero error code 1.

 

I'm scrolling through Google but nothing is helping at the moment.

Was wondering if anyone else has experienced the same issue

Labels (3)
0 Karma

vikas_gopal
Builder

Hi There ,

Are you able to resolve this issue ? if yes please post your workaround as I am also facing same issue .

0 Karma

jhilton90
Path Finder

Unfortunately not no

0 Karma

vikas_gopal
Builder

sure thank you , I am trying to reach out to the addon creator and trying few things here . Will update here in case I come with something 

0 Karma

vikas_gopal
Builder

Issue has been resolved after we provide admin permission to all the respective knowledge objects of this addon , like saved searches , lookups . I do not see this error any more 

0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...