IBM Security QRadar SOAR

 View Only
Expand all | Collapse all

Resilient Integration for Splunk and Splunk ES

  • 1.  Resilient Integration for Splunk and Splunk ES

    Posted Tue November 10, 2020 11:38 AM
    Hello All,

    I have downloaded the Resilient app from splunk base and installed on the Splunk. 
    While i was trying to setup the app i am receiving below errors:
    " Error while posting to url=/servicesNS/nobody/SA-Resilient/admin/sa_resilientconfig/config"

    Please help.

    ------------------------------
    AYUSH CHOUDHARY
    ------------------------------


  • 2.  RE: Resilient Integration for Splunk and Splunk ES

    Posted Thu November 12, 2020 10:23 AM
    Hello Ayush,

    I apologize for the delay. Unfortunately, the error that you are seeing is a very general message that Splunk displays through the UI anytime something goes wrong when you are trying to configure the Resilient Add-on. It often times can be very misleading! The real detail will be in the log file for the setup process: $SPLUNK_HOME/var/log/splunk/resilient_config_handler.log. Can you hit "setup" again in the app and post the contents of this file?

    What version of splunk are you on?
    What version of our splunk app are you using?

    Also, please have a look at the latest docs we have published for this integration if you haven't already: https://github.com/ibmresilient/resilient-reference/tree/master/developer_guides/resilient-splunk-addon

    Thanks,
    Brian

    ------------------------------
    Brian Reid
    ------------------------------