Splunk Enterprise Security
Highlighted

Recorded future app missing session key

New Member

When searching for sourcetype=recorded future IOCS, i receive the following error. I updated the API key and that fixed the issue of not being able to authenticate but now I am receiving this error. Is there somewhere within the config i need to stop the script from being started via Command line?

No session key was provided by the Splunk server. This can happen if the script is started from the command line which is not supported.
Traceback (most recent call last):
File "/opt/splunk/etc/apps/TA-recordedfuture/bin/get-rf-threatlists.py", line 186, in main
session
key = rfsplunk.apikey.getsessionkey()
File "/opt/splunk/etc/apps/TA-recordedfuture/bin/rfsplunk/apikey.py", line 85, in getsession_key
raise MissingSessionKeyError('No session key was provided by the '
MissingSessionKeyError: No session key was provided by the Splunk server. This can happen if the script is started from the command line which is not supported.

0 Karma
Highlighted

Re: Recorded future app missing session key

New Member

There is not enough data here to analyze the issue. Please open a support ticket through your support channel at Recorded Future.

0 Karma