Carbon Black Cloud: CEL alert_v7 400 bad request

The Integration Disclaimer reads, that the Alerts-API (v6) for this integration would be deactivated on July 31, 2024. We should transition to CEL input and the alert_v7 data stream. So we did & the Agent holding the Integration becomes "unhealthy" with this error message:

We still receive alerts as well, so API keys, secrets etc are working:

We didn't change any of the default interval settings:

Is there a way to get this working without these errors?

Hi @syk, thanks for reporting this issue.

@exdghost could you assist please?

I take that for an answer (screenshot below) - thanks!

after updating the integration it's even more broken and doesn't produce a valid API-request anymore but this:

  failed eval: ERROR: <input>:25:51: no such overload
   |  ).do_request().as(resp, (resp.StatusCode == 200) ?
   | ..................................................^

...but the search time range errors are gone - at least something, I guess...

I think I have a cause for this. Sending a fix now.

With Version 2.5.3 of the Integration (Screenshot below) it now works as expected - Thanks a lot @efd6 for your effort!

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.