remg427 / misp42splunk

A Splunk app to use MISP in background
GNU Lesser General Public License v3.0
109 stars 30 forks source link

Splunk Cloud compatibility #210

Closed adrinavaascap closed 2 years ago

adrinavaascap commented 2 years ago

Hello,

I am trying to connect this app with a MISP instance by using Splunk Cloud. When I create the connection with the MISP server I did not get any traffic from Splunk on the MISP server. Is there any incompatibility between Splunk Cloud and this app?

Thank you very much in advance.

Munstar0s commented 2 years ago

the error we've been receiving after setting up MIS42Splunk is "Restricting results of the "rest" operator to the local instance because you do not have the "dispatch_rest_to_indexers" capability." would appreciate help in figuring out whether this is a splunk side issue or MISP instance as im unable to find any reference or solution on the net.

remg427 commented 2 years ago

Hello, I have submitted version 4.1.0 with requested update for cloud compatibility. Appinspect is fine with automatic checks all good. Now outcome is pending manual checks (13) but given reports should be fine