In this article
A Data Export configuration returns an error message for two common reasons:
- The access credentials or region settings have changed
- The configuration settings are incorrect, missing, or were updated during or after configuration
An email is sent after 20 errors occurr.
Misaligned Data Export and AWS or Splunk values
To align the Data Export configuration with AWS or Splunk:
- From the DNSFilter dashboard, navigate to Tools and select Data Exports.
- Select Edit.
- Compare the current settings to the AWS or Splunk configuration.
- Update the data export configuration to align with AWS or Splunk.
- Select Verify & Test Account to confirm the error is resolved.
If the configurations are aligned and the error persists, continue with the following troubleshooting steps.
Look for a bad request in a HAR file
If the misalignment is not apparent from comparing the two value sets, use Developer Tools to capture a HAR file and examine the requests.
To find the error in a HAR file:
- Create a HAR file, retrying the verification while capturing the HAR.
- Open the file and look for an error message, such as
incorrect DCE URL - Correct the error in the DNSFilter dashboard.
- Select Verify & Test Account to confirm the error is resolved.
Restart a paused export with the API
If the export has moved to a Paused state and the SIEM is back online, use the following API call to clear the errors and restart the export with the saved connection settings. SIEM credentials do not need to be re-entered.
POST /v1/exports/{organization_id}/setting/reenable Authorization: Bearer <API key>A successful call returns 200 with an empty body. Replace {organization_id} with the ID of the organization whose export is paused. Restart a paused export as soon as the SIEM is reachable again.
Note: The API key must belong to a user with the Owner or Administrator role.
Alternatively, restart the export from the dashboard.
Comments
0 comments
Please sign in to leave a comment.