All Apps and Add-ons

sentinelone app no longer able to connect to sentinelone

Dallastek1
Path Finder

We have been using the sentinelone app for splunk cloud for over year lately we are getting the below error. Tried regenerating the api key, no joy

error_message="[HTTP 404] https://127.0.0.1:8089/servicesNS/nobody/sentinelone_app_for_splunk/configs/conf-authhosts/278c8-73f2-d67a-0211-782344bd8727?output_mode=json" error_type="<class 'splunk.ResourceNotFound'>" error_arguments="[HTTP 404] https://127.0.0.1:8089/servicesNS/nobody/sentinelone_app_for_splunk/configs/conf-authhosts/278c8-73f2-d67a-0211-782344bd8727?output_mode=json" error_filename="s1_client.py" error_line_number="164" input_guid="f6cf841-8787-761-d820-d0d36cebfa" input_name="Activity"


Error filename: s1_client.py

Error line number: 164

Input guid:  f6cf841-8787-761-d820-d0d36cebfa

Message:  [HTTP 404] https://127.0.0.1:8089/servicesNS/nobody/sentinelone_app_for_splunk/configs/conf-authhosts/278c8-73f2-d67a-0211-782344bd8727?output_mode=json 

 

Labels (2)
0 Karma

kareem
Explorer

I am also experiencing this issue and have yet to find a solution. I am hopeful that the community will provide an answer to this problem.

0 Karma

Dallastek1
Path Finder

working with support for our cloud instance

They removed the passwords.conf file due to the old api key still being in there and not being removed when you update it with a newly generated api key.

I then regenerated a new api key verified correct permissions in S1 and that resolved the issue.

 

Also note that sentinelone changed the length of time for a reqular user acct to have a api key to only 30 days.

This was used by a previous admin so i created a new service acct just for splunk logs, and in there you can specify longer key life (30d, 60d, 90d ect).

0 Karma

lespinosas
Explorer

Hi, please can you help me as well?

Hi @Dallastek1 
Which app did you install in Splunk Cloud for the integration?

Did you use a HF as well?

 

I tried to configure more than one "API Key" and URL but just don't succed.

 

Can you explain the steps you take?

Regards.

0 Karma

Dallastek1
Path Finder
0 Karma

lespinosas
Explorer

Thanks @Dallastek1 

Did you use just this app in Cloud or also another app (IA, TA add-ons) on Heavy Forwarder?

 

0 Karma

anglewwb35
Explorer

Hi i am new to splunk. As I am trying to integrate splunk with sentinelone, I found it frustrated to find which api key/token should I use... ( The SDL one or Management Console one). Also, I cannot find what the url and name should be under the Application Configuration page in Splunk. Hope you can help... Many thanks

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...