twistlock / sample-code

Sample code for Prisma Cloud Compute (formerly Twistlock)
https://www.paloaltonetworks.com/prisma/cloud
MIT License
93 stars 95 forks source link

Archived/Missing Incidents fail on request. #118

Closed mwilco03 closed 2 years ago

mwilco03 commented 3 years ago

In code when the incident has been archive/can't be found app errors out and makes Splunk log roll. Possible courses of action:

This error presents in environments with re-building infrastructure primarily.

wfg commented 3 years ago

Is this the line that is causing the excess logging? https://github.com/twistlock/sample-code/blob/e780463ebcf1c3e2e88c324743b2d9780fb445f4/siem/splunk/twistlock/bin/poll_forensics.py#L59

Edit: add permalink

wfg commented 2 years ago

@mwilco03 if this is still an issue, please reopen the issue in the new dedicated repo for the Splunk app: https://github.com/PaloAltoNetworks/prisma-cloud-compute-splunk