Splunk SOAR

Reversing Labb Testing Connectivity Failed

johnteo
Explorer

Hi all, my attempt to set up reversing labs app in Splunk Phantom has run into an error.

It says:
Connectivity test failed. Please check your credentials or the network connectivity. HTTP status_code: 401, reason; UNAUTHORIZED. https://ticloud-aws1-api.reversinglabs.com/api/databrowser/malware_presence/bulk_query/json?extended.... No action executions found.

How do I troubleshoot and resolve this error?

Labels (1)
Tags (1)
0 Karma
1 Solution

phantom_mhike
SplunkTrust
SplunkTrust

This error suggests that either you are not a reversinglabs customer or your credentials have been input incorrectly in the phantom asset. The test connectivity function simply reaches out to the reversinglabs service and tests the credentials you used and yours returned a 401 unauthorized response. If you are already a reversing labs customer, make sure your credentials work outside of phantom and then try adding them to the asset again. If that doesnt work, you will need to resolve the access issue with reversinglabs. If you arent a reversinglabs customer, then this particular integration isnt going to work for you.

View solution in original post

phantom_mhike
SplunkTrust
SplunkTrust

This error suggests that either you are not a reversinglabs customer or your credentials have been input incorrectly in the phantom asset. The test connectivity function simply reaches out to the reversinglabs service and tests the credentials you used and yours returned a 401 unauthorized response. If you are already a reversing labs customer, make sure your credentials work outside of phantom and then try adding them to the asset again. If that doesnt work, you will need to resolve the access issue with reversinglabs. If you arent a reversinglabs customer, then this particular integration isnt going to work for you.

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...