Getting Data In

Get error message: command="darklist", 'URLError' object has no attribute 'code'

addproniklas
Engager

Hi,

Im getting a error message when running the savedsearch "Norse - Download Norse Darklist" after i have provided the app with an valid API key.
The error message is:

command="darklist", 'URLError' object has no attribute 'code'

Could someone please help me to figure out what im doing wrong and how to fix it?

BR
/Nik,Hi,

I'm trying to get the Norse App to work, but with no luck.
I've provided the app with my API key, but when i run the savedsearch "Norse - Download Norse Darklist" i get the following error message:

command="darklist", 'URLError' object has no attribute 'code'

Can you please help me to figure out what im doing wrong and what i can do to fix it?

Br
Nik

1 Solution

jcoates_splunk
Splunk Employee
Splunk Employee

Hi, we believe this to be because the Norse API has changed; the old API that this Add-on uses is no longer functional. This Add-on is consequently at its end of life... We believe it will need restructuring to be usable with the new API.

View solution in original post

0 Karma

jcoates_splunk
Splunk Employee
Splunk Employee

Hi, we believe this to be because the Norse API has changed; the old API that this Add-on uses is no longer functional. This Add-on is consequently at its end of life... We believe it will need restructuring to be usable with the new API.

0 Karma

baldwintm
Path Finder

It looks like this is trying to connect to http://darklist.ipviking.net/slice
The connection is timing out. It looks like that server is no longer listening on port 80.
(It currently resolves to: 64.19.78.10)

0 Karma

subnet
New Member

Could be a bandwidth or connection issue if you are going through a proxy. Try running

| norse_download_darklist | outputlookup norse_darklist_lookup

If you still have issue, then most likely bandwidth/connection.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...