Splunk SOAR (f.k.a. Phantom)

Reversing Labb Testing Connectivity Failed

johnteo
Explorer

Hi all, my attempt to set up reversing labs app in Splunk Phantom has run into an error.

It says:
Connectivity test failed. Please check your credentials or the network connectivity. HTTP status_code: 401, reason; UNAUTHORIZED. https://ticloud-aws1-api.reversinglabs.com/api/databrowser/malware_presence/bulk_query/json?extended.... No action executions found.

How do I troubleshoot and resolve this error?

Labels (1)
Tags (1)
0 Karma
1 Solution

phantom_mhike
SplunkTrust
SplunkTrust

This error suggests that either you are not a reversinglabs customer or your credentials have been input incorrectly in the phantom asset. The test connectivity function simply reaches out to the reversinglabs service and tests the credentials you used and yours returned a 401 unauthorized response. If you are already a reversing labs customer, make sure your credentials work outside of phantom and then try adding them to the asset again. If that doesnt work, you will need to resolve the access issue with reversinglabs. If you arent a reversinglabs customer, then this particular integration isnt going to work for you.

View solution in original post

phantom_mhike
SplunkTrust
SplunkTrust

This error suggests that either you are not a reversinglabs customer or your credentials have been input incorrectly in the phantom asset. The test connectivity function simply reaches out to the reversinglabs service and tests the credentials you used and yours returned a 401 unauthorized response. If you are already a reversing labs customer, make sure your credentials work outside of phantom and then try adding them to the asset again. If that doesnt work, you will need to resolve the access issue with reversinglabs. If you arent a reversinglabs customer, then this particular integration isnt going to work for you.

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...