Splunk SOAR (f.k.a. Phantom)

Reversing Labb Testing Connectivity Failed

johnteo
Explorer

Hi all, my attempt to set up reversing labs app in Splunk Phantom has run into an error.

It says:
Connectivity test failed. Please check your credentials or the network connectivity. HTTP status_code: 401, reason; UNAUTHORIZED. https://ticloud-aws1-api.reversinglabs.com/api/databrowser/malware_presence/bulk_query/json?extended.... No action executions found.

How do I troubleshoot and resolve this error?

Labels (1)
Tags (1)
0 Karma
1 Solution

phantom_mhike
SplunkTrust
SplunkTrust

This error suggests that either you are not a reversinglabs customer or your credentials have been input incorrectly in the phantom asset. The test connectivity function simply reaches out to the reversinglabs service and tests the credentials you used and yours returned a 401 unauthorized response. If you are already a reversing labs customer, make sure your credentials work outside of phantom and then try adding them to the asset again. If that doesnt work, you will need to resolve the access issue with reversinglabs. If you arent a reversinglabs customer, then this particular integration isnt going to work for you.

View solution in original post

phantom_mhike
SplunkTrust
SplunkTrust

This error suggests that either you are not a reversinglabs customer or your credentials have been input incorrectly in the phantom asset. The test connectivity function simply reaches out to the reversinglabs service and tests the credentials you used and yours returned a 401 unauthorized response. If you are already a reversing labs customer, make sure your credentials work outside of phantom and then try adding them to the asset again. If that doesnt work, you will need to resolve the access issue with reversinglabs. If you arent a reversinglabs customer, then this particular integration isnt going to work for you.

Get Updates on the Splunk Community!

Modern way of developing distributed application using OTel

Recently, I had the opportunity to work on a complex microservice using Spring boot and Quarkus to develop a ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had 3 releases of new security content via the Enterprise Security ...

Archived Metrics Now Available for APAC and EMEA realms

We’re excited to announce the launch of Archived Metrics in Splunk Infrastructure Monitoring for our customers ...