Splunk SOAR (f.k.a. Phantom)

Invalid token in Splunk app for SOAR, yet tokens are the same

schimpanze
Engager

Hello community,

I have come across the issue when I got identical token generated for SOAR user "REST" that I am using for SIEM-SOAR integration and the same was in the Splunk app for SOAR.

When I run "test connectivity" command on the SOAR Server Configuration, it responded with "Authentication Failed: Invalid token".

I have just regenerated the token and everything works like a charm.

Have you ever encountered such issue?

0 Karma
1 Solution

phanTom
SplunkTrust
SplunkTrust

@schimpanze what version are you on? IIRC there was a bug where automation tokens got auto rotated every 30 days, so you may have fell victim to this?

 

It will be on the Known Issues page of the release version you have if you want to check. 

View solution in original post

Tags (1)

phanTom
SplunkTrust
SplunkTrust

Yes the latest version definitely fixes this and AFAIK is a good, stable version too with lots of other bug fixes.

0 Karma

schimpanze
Engager

@phanTom we are running version 6.0.0.114895 so basically we fit the scope of the Known issue you are referring to. It is good to know that this page exists, I had no idea so far. Thank you!

It seems that upgrading to the latest release 6.1.1 would do the trick and get us rid of this 30d rotation, don't you think?

0 Karma

phanTom
SplunkTrust
SplunkTrust

@schimpanze what version are you on? IIRC there was a bug where automation tokens got auto rotated every 30 days, so you may have fell victim to this?

 

It will be on the Known Issues page of the release version you have if you want to check. 

Tags (1)
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...