We recently updated Splunk to version 9.4.9 and found that our Cofense logs stopped flowing soon after. We are on version 2.1.7 of the Cofense Triage Add-On, which does say supports 9.4.x in the release notes. However, there appears to be a discrepancy in the readme of the Add-on where 9.4 is missing from the compatible versions list. It does mention 9.3 twice, so I suspect that is a typo.
My Splunk team is reporting that they believe 2.1.7 is incompatible with 9.4. The error the TA in Splunk shows appears to be more related to a python error. Has anyone run into this before?
Error:
External handler failed with code '1' and output: ''.
Hi @zpadams
The app is supported/maintained by Cofense - I would recommend emailing them at [email protected] to enquire/report this and hopefully they can resolve for you.
🌟 Did this answer help you? If so, please consider:
Your feedback encourages the volunteers in this community to continue contributing.