Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Getinfo probe failed for external search command 'mispsight' #236

Closed
J1mb0S1ic3 opened this issue Jun 28, 2023 · 5 comments
Closed

Getinfo probe failed for external search command 'mispsight' #236

J1mb0S1ic3 opened this issue Jun 28, 2023 · 5 comments

Comments

@J1mb0S1ic3
Copy link

J1mb0S1ic3 commented Jun 28, 2023

We have confirmed connectivity of this app to our MISP instance, using command:
| mispcollect misp_instance=Preprod eventid="81" endpoint="events"

We however try to run the command below:
index= src= | regex src=\d+.\d+.\d+.\d+ | mispsight field=src misp_instance=Preprod**

And we get an error:
Streamed search execute failed because: Error in 'script': Getinfo probe failed for external search command 'mispsight'..

Looking in search.log we see the following:
06-27-2023 13:45:54.091 ERROR ScriptRunner [929833 localCollectorThread] - stderr from '/opt/splunk/bin/nsjail-wrapper /opt/splunk/bin/python3.7 /opt/splunk/etc/apps/misp42splunk/bin/mispsight.py EXECUTE field=src misp_instance=Preprod': [SI-101] logging level is set to DEBUG
06-27-2023 13:45:54.091 ERROR ScriptRunner [929833 localCollectorThread] - stderr from '/opt/splunk/bin/nsjail-wrapper /opt/splunk/bin/python3.7 /opt/splunk/etc/apps/misp42splunk/bin/mispsight.py EXECUTE field=src misp_instance=Preprod': [SI-102] PYTHON VERSION: 3.7.16 (default, Mar 22 2023, 01:29:27)
06-27-2023 13:45:54.091 ERROR ScriptRunner [929833 localCollectorThread] - stderr from '/opt/splunk/bin/nsjail-wrapper /opt/splunk/bin/python3.7 /opt/splunk/etc/apps/misp42splunk/bin/mispsight.py EXECUTE field=src misp_instance=Preprod': [GCC 9.2.0]
06-27-2023 13:45:54.091 ERROR ScriptRunner [929833 localCollectorThread] - stderr from '/opt/splunk/bin/nsjail-wrapper /opt/splunk/bin/python3.7 /opt/splunk/etc/apps/misp42splunk/bin/mispsight.py EXECUTE field=src misp_instance=Preprod': GET request to https://127.0.0.1:8089/servicesNS/nobody/search/misp42splunk_instances (body: {})
06-27-2023 13:45:54.235 ERROR ScriptRunner [929833 localCollectorThread] - stderr from '/opt/splunk/bin/nsjail-wrapper /opt/splunk/bin/python3.7 /opt/splunk/etc/apps/misp42splunk/bin/mispsight.py EXECUTE field=src misp_instance=Preprod': Operation took 0:00:00.143451
06-27-2023 13:45:54.235 ERROR ScriptRunner [929833 localCollectorThread] - stderr from '/opt/splunk/bin/nsjail-wrapper /opt/splunk/bin/python3.7 /opt/splunk/etc/apps/misp42splunk/bin/mispsight.py EXECUTE field=src misp_instance=Preprod': [MC-PC-D01] response.status=200
06-27-2023 13:45:54.236 ERROR ScriptRunner [929833 localCollectorThread] - stderr from '/opt/splunk/bin/nsjail-wrapper /opt/splunk/bin/python3.7 /opt/splunk/etc/apps/misp42splunk/bin/mispsight.py EXECUTE field=src misp_instance=Preprod': [MC-PC-D02] instance_count=1
06-27-2023 13:45:54.236 ERROR ScriptRunner [929833 localCollectorThread] - stderr from '/opt/splunk/bin/nsjail-wrapper /opt/splunk/bin/python3.7 /opt/splunk/etc/apps/misp42splunk/bin/mispsight.py EXECUTE field=src misp_instance=Preprod': [MC-PC-D03] single instance={'title': 'Preprod', 'id': 'https://127.0.0.1/servicesNS/nobody/misp42splunk/misp42splunk_instances/Preprod', 'updated': '1970-01-01T00:00:00+00:00', 'link': [{'href': '/servicesNS/nobody/misp42splunk/misp42splunk_instances/Preprod', 'rel': 'alternate'}, {'href': '/servicesNS/nobody/misp42splunk/misp42splunk_instances/Preprod', 'rel': 'list'}, {'href': '/servicesNS/nobody/misp42splunk/misp42splunk_instances/Preprod', 'rel': 'edit'}, {'href': '/servicesNS/nobody/misp42splunk/misp42splunk_instances/Preprod', 'rel': 'remove'}], 'author': {'name': ''}, 'content': {'disabled': '0', 'eai:acl': {'app': 'misp42splunk', 'can_change_perms': '1', 'can_list': '1', 'can_share_app': '1', 'can_share_global': '1', 'can_share_user': '1', 'can_write': '1', 'modifiable': '1', 'owner': ['](', 'perms': {'read': [''], 'write': ['admin']}, 'removable': '1', 'sharing': 'global'}, 'eai:appName': 'misp42splunk', 'eai:userName': 'nobody', 'misp_key': '*****', 'misp_url': '', 'misp_verifycert': '0', 'type': 'text/xml'}}
06-27-2023 13:45:54.236 ERROR ScriptRunner [929833 localCollectorThread] - stderr from '/opt/splunk/bin/nsjail-wrapper /opt/splunk/bin/python3.7 /opt/splunk/etc/apps/misp42splunk/bin/mispsight.py EXECUTE field=src misp_instance=Preprod': GET request to https://127.0.0.1:8089/servicesNS/nobody/search/storage/passwords (body: {'count': -1, 'offset': 0})
06-27-2023 13:45:54.249 ERROR ScriptRunner [929833 localCollectorThread] - stderr from '/opt/splunk/bin/nsjail-wrapper /opt/splunk/bin/python3.7 /opt/splunk/etc/apps/misp42splunk/bin/mispsight.py EXECUTE field=src misp_instance=Preprod': Operation took 0:00:00.012962
06-27-2023 13:45:54.269 ERROR ScriptRunner [929833 localCollectorThread] - stderr from '/opt/splunk/bin/nsjail-wrapper /opt/splunk/bin/python3.7 /opt/splunk/etc/apps/misp42splunk/bin/mispsight.py EXECUTE field=src misp_instance=Preprod': MispSightCommand.process finished under protocol_version=1

Is there a permissions issue or problem with the jailer that is running our mispsight.py script?

We have reported the same issue to splunk cloud support, will see what they say.

@J1mb0S1ic3
Copy link
Author

I just had word from splunk support, they said our search head isnt part of a search head cluster, it's a standalone, and that is the reason for this error? Is anyone able to clarify if this is the case?

@remg427
Copy link
Owner

remg427 commented Jun 30, 2023 via email

@J1mb0S1ic3
Copy link
Author

Hi, we are on splunk 9 in the cloud and the latest version of the MISP app 4.2.2.

@J1mb0S1ic3
Copy link
Author

Hi, has any testing been completed with regards to this being only compatible with a SHC?

@remg427
Copy link
Owner

remg427 commented Oct 12, 2024

mispsight works on standalone search head and also cluster. closing

@remg427 remg427 closed this as completed Oct 12, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants