All Apps and Add-ons

Splunk Add-on for Cisco IPS: Why am I getting "HTTP Error 401: Unauthorized"?

vinchakov_a
Path Finder
Thu Apr  9 09:12:16 2015 - ERROR - Attempting to re-connect to the sensor: 172.16.23.50
Thu Apr  9 09:12:19 2015 - INFO - Checking for existing SubscriptionID on host: 172.16.23.50
Thu Apr  9 09:12:19 2015 - INFO - Attempting to connect to sensor: 172.16.23.50
Thu Apr  9 09:12:19 2015 - INFO - Successfully connected to: 172.16.23.50
Thu Apr  9 09:12:38 2015 - ERROR - Exception thrown in sdee.get(): Traceback (most recent call last):   File "/opt/splunk/etc/apps/Splunk_TA_cisco-ips/bin/get_ips_feed.py", line 113, in run     sdee.get()   File "/opt/splunk/etc/apps/Splunk_TA_cisco-ips/bin/pysdee/pySDEE.py", line 211, in get     self._request(params, **kwargs)   File "/opt/splunk/etc/apps/Splunk_TA_cisco-ips/bin/pysdee/pySDEE.py", line 163, in _request     data = urllib2.urlopen(req)   File "/opt/splunk/lib/python2.7/urllib2.py", line 127, in urlopen     return _opener.open(url, data, timeout)   File "/opt/splunk/lib/python2.7/urllib2.py", line 410, in open     response = meth(req, response)   File "/opt/splunk/lib/python2.7/urllib2.py", line 523, in http_response     'http', request, response, code, msg, hdrs)   File "/opt/splunk/lib/python2.7/urllib2.py", line 448, in error     return self._call_chain(*args)   File "/opt/splunk/lib/python2.7/urllib2.py", line 382, in _call_chain     result = func(*args)   File "/opt/splunk/lib/python2.7/urllib2.py", line 531, in http_error_default     raise HTTPError(req.get_full_url(), code, msg, hdrs, fp) HTTPError: HTTP Error 401: Unauthorized 
Thu Apr  9 09:12:38 2015 - ERROR - Attempting to re-connect to the sensor: 172.16.23.50
Thu Apr  9 09:12:42 2015 - INFO - Checking for existing SubscriptionID on host: 172.16.23.50
Thu Apr  9 09:12:42 2015 - INFO - Attempting to connect to sensor: 172.16.23.50
Thu Apr  9 09:12:42 2015 - INFO - Successfully connected to: 172.16.23.50
0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

There are two potential reasons:
- The device wants a different SSL or TLS configuration than you're using. Make sure you're on the latest Add-on and latest device firmware, and double-check configurations
- The device is busy and not giving a good error message.

0 Karma

bmas10
Explorer

I am seeing the same errors on devices that aren't busy and have been configured to use TLSv1_1 in pySDEE.py. Still not love. Any other ideas?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...