welcome-to-rubrik-build
welcome-to-rubrik-build copied to clipboard
Rubrik add-on for Splunk v1.1.3 reporting errors querying Polaris since 10th May. Please review and correct the add on
Expected Behavior
API complete and detailed added to Splunk add on
Current Behavior
What is the current behavior?
Reporting issues with Splunk 8.2.5 communicating with Rubrik Polaris. Rubrik add-on for Splunk; v1.1.3.
Splunk was communicating fine until May 10th ( 5/10/22 ). Changes to the Polaris API seems to have caused issues with the query's from the Rubrik Splunk add-on. Confirmed with the Polaris API-server team changes were performed
Polaris events we see for the account +++ Time msg May 26, 2022 @ 16:46:20.594 Client Error: (400) [/api/graphql] [QueryAnalysisError] [Watchers Team] Encountered Client error (400) executing query with operations: [eventSeriesList] and variables {"filters":{"objectType":[],"lastActivityStatus":[],"lastActivityType":["Anomaly"],"severity":[],"cluster":{"id":[]},"lastUpdated_gt":"2022-05-26T15:16:20Z","objectName":""},"first":20}. Error: Error during variable coercion. Violations: +++
The attached Image shows the errors reported on the Splunk Server when trying to connect Polaris. (user is correct and no issues)