welcome-to-rubrik-build icon indicating copy to clipboard operation
welcome-to-rubrik-build copied to clipboard

Rubrik add-on for Splunk v1.1.3 reporting errors querying Polaris since 10th May. Please review and correct the add on

Open CLRUBRIK opened this issue 2 years ago • 0 comments

Expected Behavior

API complete and detailed added to Splunk add on

Current Behavior

What is the current behavior?

Reporting issues with Splunk 8.2.5 communicating with Rubrik Polaris. Rubrik add-on for Splunk; v1.1.3.

Splunk was communicating fine until May 10th ( 5/10/22 ). Changes to the Polaris API seems to have caused issues with the query's from the Rubrik Splunk add-on. Confirmed with the Polaris API-server team changes were performed

Polaris events we see for the account +++ Time msg May 26, 2022 @ 16:46:20.594 Client Error: (400) [/api/graphql] [QueryAnalysisError] [Watchers Team] Encountered Client error (400) executing query with operations: [eventSeriesList] and variables {"filters":{"objectType":[],"lastActivityStatus":[],"lastActivityType":["Anomaly"],"severity":[],"cluster":{"id":[]},"lastUpdated_gt":"2022-05-26T15:16:20Z","objectName":""},"first":20}. Error: Error during variable coercion. Violations: +++

The attached Image shows the errors reported on the Splunk Server when trying to connect Polaris. (user is correct and no issues) copy 1 of splunkapipolariserror

CLRUBRIK avatar May 27 '22 08:05 CLRUBRIK