We have been using the sentinelone app for splunk cloud for over year lately we are getting the below error. Tried regenerating the api key, no joy
error_message="[HTTP 404] https://127.0.0.1:8089/servicesNS/nobody/sentinelone_app_for_splunk/configs/conf-authhosts/278c8-73f2-d67a-0211-782344bd8727?output_mode=json" error_type="<class 'splunk.ResourceNotFound'>" error_arguments="[HTTP 404] https://127.0.0.1:8089/servicesNS/nobody/sentinelone_app_for_splunk/configs/conf-authhosts/278c8-73f2-d67a-0211-782344bd8727?output_mode=json" error_filename="s1_client.py" error_line_number="164" input_guid="f6cf841-8787-761-d820-d0d36cebfa" input_name="Activity"
Error filename: s1_client.py
Error line number: 164
Input guid: f6cf841-8787-761-d820-d0d36cebfa
Message: [HTTP 404] https://127.0.0.1:8089/servicesNS/nobody/sentinelone_app_for_splunk/configs/conf-authhosts/278c8-73f2-d67a-0211-782344bd8727?output_mode=json
I am also experiencing this issue and have yet to find a solution. I am hopeful that the community will provide an answer to this problem.
working with support for our cloud instance
They removed the passwords.conf file due to the old api key still being in there and not being removed when you update it with a newly generated api key.
I then regenerated a new api key verified correct permissions in S1 and that resolved the issue.
Also note that sentinelone changed the length of time for a reqular user acct to have a api key to only 30 days.
This was used by a previous admin so i created a new service acct just for splunk logs, and in there you can specify longer key life (30d, 60d, 90d ect).
Hi, please can you help me as well?
Hi @Dallastek1
Which app did you install in Splunk Cloud for the integration?
Did you use a HF as well?
I tried to configure more than one "API Key" and URL but just don't succed.
Can you explain the steps you take?
Regards.
Thanks @Dallastek1
Did you use just this app in Cloud or also another app (IA, TA add-ons) on Heavy Forwarder?
Hi i am new to splunk. As I am trying to integrate splunk with sentinelone, I found it frustrated to find which api key/token should I use... ( The SDL one or Management Console one). Also, I cannot find what the url and name should be under the Application Configuration page in Splunk. Hope you can help... Many thanks