# Carbon Black Cloud: CEL alert\_v7 400 bad request

**URL:** <https://discuss.elastic.co/t/carbon-black-cloud-cel-alert-v7-400-bad-request/366464>\
**Category:** SIEM\
**Created:** [September 12, 2024, 10:24am UTC](https://discuss.elastic.co/t/carbon-black-cloud-cel-alert-v7-400-bad-request/366464 "2024-09-12T10:24:48Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![syk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syk/32/141533_2.png) [@syk](https://discuss.elastic.co/u/syk)\
**Post date:** [September 12, 2024, 10:24am UTC](https://discuss.elastic.co/t/carbon-black-cloud-cel-alert-v7-400-bad-request/366464/1 "2024-09-12T10:24:48Z")

</div>

The Integration Disclaimer reads, that the Alerts-API (v6) for this integration would be deactivated on July 31, 2024. We should transition to CEL input and the alert\_v7 data stream. So we did & the Agent holding the Integration becomes "unhealthy" with this error message:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/f/dfe357dd2cf37ad79d364a267dc816cdcc1627ca.png)

We still receive alerts as well, so API keys, secrets etc are working:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/c/ac96d36e905c25864a372f6323fc4bcad568219c.png)

We didn't change any of the default interval settings:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/9/79717fd20584af846379805b9e290b9546fd05c6.png)

Is there a way to get this working without these errors?

---

<div class="post-metadata">

**Author:** ![jamie.hynds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamie.hynds/32/84205_2.png) [@jamie.hynds](https://discuss.elastic.co/u/jamie.hynds)\
**Post date:** [September 12, 2024, 1:12pm UTC](https://discuss.elastic.co/t/carbon-black-cloud-cel-alert-v7-400-bad-request/366464/2 "2024-09-12T13:12:39Z")

</div>

Hi @syk, thanks for reporting this issue.

@exdghost could you assist please?

---

<div class="post-metadata">

**Author:** ![syk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syk/32/141533_2.png) [@syk](https://discuss.elastic.co/u/syk)\
**Post date:** [September 20, 2024, 5:36am UTC](https://discuss.elastic.co/t/carbon-black-cloud-cel-alert-v7-400-bad-request/366464/3 "2024-09-20T05:36:09Z")

</div>

I take that for an answer (screenshot below) - thanks!

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/4/4/441b674a52a1862ce97b404d3931d4a0a3fb625a.png)

---

<div class="post-metadata">

**Author:** ![syk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syk/32/141533_2.png) [@syk](https://discuss.elastic.co/u/syk)\
**Post date:** [September 20, 2024, 5:50am UTC](https://discuss.elastic.co/t/carbon-black-cloud-cel-alert-v7-400-bad-request/366464/4 "2024-09-20T05:50:28Z")

</div>

after updating the integration it's even more broken and doesn't produce a valid API-request anymore but this:

```auto
  failed eval: ERROR: <input>:25:51: no such overload
   | ).do_request().as(resp, (resp.StatusCode == 200) ?
   | ..................................................^

```

...but the search time range errors are gone - at least something, I guess...

---

<div class="post-metadata">

**Author:** ![efd6](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/efd6/32/94818_2.png) [@efd6](https://discuss.elastic.co/u/efd6)\
**Post date:** [September 23, 2024, 10:37pm UTC](https://discuss.elastic.co/t/carbon-black-cloud-cel-alert-v7-400-bad-request/366464/5 "2024-09-23T22:37:25Z")

</div>

I think I have a cause for this. Sending a fix now.

> <https://github.com/elastic/integrations/pull/11221>
>
> \<!-- Type of change
> Please label this PR with one of the following labels, depe…nding on the scope of your change:
> \- Bug
> \- Enhancement
> \- Breaking change
> \- Deprecation
> \--\>
> 
> \## Proposed commit message
> 
> \<!-- Mandatory
> Explain here the changes you made on the PR.
> 
> Please explain:
> 
> \- WHAT: patterns used, algorithms implemented, design architecture, message processing, etc.
> \- WHY: the rationale/motivation for the changes
> 
> This text will be pasted into the squash dialog when the change is committed and will be
> a long term historical record of the change to help future contributors understand the
> change, please help them by making it clear and comprehensive, they may be you.
> 
> If the commit title is adequate to describe both of these things, The text here may be omitted
> or replaced with "See title". The title of the PR will be used as the commit message title when
> the merge is made and the "See title" marker will be removed if present.
> 
> The text here and the PR title will be subject to the PR review process.
> \--\>
> 
> When using the cursor value, the start expression in the range macro is a string since state.cursor.last\_backend\_update\_timestamp is a string. This results in a comparison of range.start (string) with range.end (timestamp) which is not a valid type match for the \\\< operator. So we end up with a "no such overload". If the value is optional.none, we use delayed (timestamp) which is the correct type. Ensure that the expression is always a timestamp by doing a conversion on the resulting value, noting that a timestamp(timestamp(x)) is valid if timestamp(x) is.
> 
> \## Checklist
> 
> \- \[\] I have reviewed \[tips for building integrations\](https://github.com/elastic/integrations/blob/main/docs/tips\_for\_building\_integrations.md) and this pull request is aligned with them.
> \- \[\] I have verified that all data streams collect metrics or logs.
> \- \[\] I have added an entry to my package's \`changelog.yml\` file.
> \- \[\] I have verified that Kibana version constraints are current according to \[guidelines\](https://github.com/elastic/elastic-package/blob/master/docs/howto/stack\_version\_support.md#when-to-update-the-condition).
> 
> \## Author's Checklist
> 
> \<!-- Recommended
> Add a checklist of things that are required to be reviewed in order to have the PR approved
> \--\>
> \- \[\] 
> 
> \## How to test this PR locally
> 
> \<!-- Recommended
> Explain here how this PR will be tested by the reviewer: commands, dependencies, steps, etc.
> \--\>
> 
> \## Related issues
> 
> \<!-- Recommended
> Link related issues below. Insert the issue link or reference after the word "Closes" if merging this should automatically close it.
> 
> \- Closes #123
> \- Relates #123
> \- Requires #123
> \- Supersedes #123
> \--\>
> \- 
> 
> \## Screenshots
> 
> \<!-- Optional
> Add here screenshots presenting:
> \- Kibana UI forms presenting configuration options exposed by the integration
> \- dashboards with collected metrics or logs
> \--\>

---

<div class="post-metadata">

**Author:** ![syk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/syk/32/141533_2.png) [@syk](https://discuss.elastic.co/u/syk)\
**Post date:** [September 27, 2024, 7:50am UTC](https://discuss.elastic.co/t/carbon-black-cloud-cel-alert-v7-400-bad-request/366464/6 "2024-09-27T07:50:18Z")

</div>

With Version 2.5.3 of the Integration (Screenshot below) it now works as expected - Thanks a lot @efd6 for your effort!

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/1/f14f74c866c104f2e637633e1938626fa665388c.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 25, 2024, 7:51am UTC](https://discuss.elastic.co/t/carbon-black-cloud-cel-alert-v7-400-bad-request/366464/7 "2024-10-25T07:51:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
