Having trouble integrating SentinelOne App for Splunk (v5.1 & 5.2) - "cannot unpack non-iterable NoneType object" & Authentication Failed
I'm encountering errors while integrating the SentinelOne App for Splunk on both versions 5.1 and 5.2. I've followed the official documentation (please specify which documentation if available) for API integration and configured everything within the app, including sourcetypes ("activities","threats","Activities","Application"etc).
when searching events for SentinelOne: [I am seeing the following error]
error_message="cannot unpack non-iterable NoneType object" error_type="<class 'TypeError'>" error_arguments="cannot unpack non-iterable NoneType object" error_filename="s1_client.py" error_line_number="496" input_guid="6xxxxxb-8xxxc-e531-e6x8-4xxxaf" input_name="edr-activities"
@sentinelone
App - https://splunkbase.splunk.com/app/5433
Hi @imarri , I have encountered this error before and I solved it by refreshing the credentials i.e the Api token. try entering a new token and see if it works.
Hi
Which is the API Token and URL did you guys use?
I try 2 different and did not have success.
I'm using Splunk Cloud with the App for SentinelOne (not the TA or IA), is that ok?
Regards
Did you resolve this? I'm having the same issue.