ZachChristensen28 / TA-crowdstrike-identities

The CrowdStrike Falcon Identity Protection Add-on for Splunk Add-on allows ingestion of the CrowdStrike identity data into Splunk enabling the data to be used with other Splunk Apps, such as Enterprise Security.
https://splunk-ta-crowdstrike.ztsplunker.com/
Other
0 stars 0 forks source link

Access Denied: 403 error #27

Closed ZachChristensen28 closed 11 months ago

ZachChristensen28 commented 11 months ago

Bug description

API credentials are set up with read/write permissions on the Identity Protection entities.

Observed in logs:

403 error "access denied, authorization failed"

Related links

TA-crowdstrike-identities Version

1.0.1

Splunk Version

9.0.1

ZachChristensen28 commented 11 months ago

New API Requirements add to docs that resolves the issue: https://splunk-ta-crowdstrike.ztsplunker.com/quickstart/api-token/