Archive

Splunk Add-on for CrowdStrike: 500 Server Error: Internal Server Error for url

Path Finder

First time setting up the Splunk version of this app, normally just use the crowdstrike version that downloads the logs and just create inputs to monitor.

2017-06-13 11:21:17,081 +0000 loglevel=ERROR, pid=31446, tid=Thread-4, file=tadatacollector.py, funcname=dosafeindex, codelineno=170 | [stanzaname="companycs"] Failed to get msg
Traceback (most recent call last):
File "/opt/app/splunk/etc/apps/Splunk
TAcrowdstrike/bin/splunktacrowdstrike/splunktaucclib/datacollection/tadatacollector.py", line 160, in dosafeindex
events, ckpt = self.
client.get()
File "/opt/app/splunk/etc/apps/SplunkTAcrowdstrike/bin/splunktacrowdstrike/falconhostdataclient.py", line 60, in get
self.
initialize()
File "/opt/app/splunk/etc/apps/SplunkTAcrowdstrike/bin/splunktacrowdstrike/falconhostdataclient.py", line 104, in _initialize
app
id=appid, proxies=proxies, name=self.stanza)
File "/opt/app/splunk/etc/apps/SplunkTAcrowdstrike/bin/splunktacrowdstrike/falconhoststreamapi.py", line 31, in consume
stream = _discover
streams(name, firehost, apiuuid, apikey, appid, proxies)
File "/opt/app/splunk/etc/apps/SplunkTAcrowdstrike/bin/splunktacrowdstrike/falconhoststreamapi.py", line 42, in _discoverstreams
proxies=proxies))
File "/opt/app/splunk/etc/apps/SplunkTAcrowdstrike/bin/splunktacrowdstrike/falconhoststreamapi.py", line 151, in _ensureresponse
response.raiseforstatus()
File "/opt/app/splunk/etc/apps/SplunkTAcrowdstrike/bin/splunktacrowdstrike/requests/models.py", line 862, in raiseforstatus
raise HTTPError(httperrormsg, response=self)
HTTPError: 500 Server Error: Internal Server Error for url: https://firehose.crowdstrike.com/sensors/entities/datafeed/v1?appId=splunk-ta-sh1.company.domainj2

0 Karma

New Member

This is due to the FalconHost Streaming API not being enabled. Upon contacting Crowdstrike Support, they enabled it for me and it solved my problem.

0 Karma

New Member

I also am experiencing this same problem. Has anyone got a solution/workaround?

0 Karma