Lookup file error, unknown path or update time
ZachChristensen28 opened this issue · 1 comments
ZachChristensen28 commented
Describe the bug
Full output of issue:
file=identity_manager.py:lookup_last_update:387 | status="Lookup file error, unknown path or update time" name=crowdstrike_devices
To Reproduce
Run the following search:
index=_internal sourcetype="identity_correlation:modular_input" ERROR
Expected behavior
No errors from the identity manager.
Screenshots
n/a
Versions (please complete the following information):
- Splunk Version: 9.0
- SA-SentinelOneDevices Version: 1.0.0
- SentinelOne App For Splunk Version: 5.1.7
- Enterprise Security Version: 7.0.1
Additional context
n/a
ZachChristensen28 commented
This error exists since the KVstore is being used as opposed to a CSV file and does not interfere with the functionality of lookup creation.