Splunk Enterprise Security

Recorded future app missing session key

jerm1020rq
Explorer

When searching for sourcetype=recorded future IOCS, i receive the following error. I updated the API key and that fixed the issue of not being able to authenticate but now I am receiving this error. Is there somewhere within the config i need to stop the script from being started via Command line?

No session key was provided by the Splunk server. This can happen if the script is started from the command line which is not supported.
Traceback (most recent call last):
File "/opt/splunk/etc/apps/TA-recorded_future/bin/get-rf-threatlists.py", line 186, in main
session_key = rf_splunk.api_key.get_session_key()
File "/opt/splunk/etc/apps/TA-recorded_future/bin/rf_splunk/api_key.py", line 85, in get_session_key
raise MissingSessionKeyError('No session key was provided by the '
MissingSessionKeyError: No session key was provided by the Splunk server. This can happen if the script is started from the command line which is not supported.

0 Karma

ess
New Member

There is not enough data here to analyze the issue. Please open a support ticket through your support channel at Recorded Future.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...