<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Web not accessible via https in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-Web-not-accessible-via-https/m-p/479020#M11060</link>
    <description>&lt;P&gt;Please provide output of &lt;CODE&gt;ss -nltp | grep 443&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 22 Apr 2020 09:01:48 GMT</pubDate>
    <dc:creator>harsmarvania57</dc:creator>
    <dc:date>2020-04-22T09:01:48Z</dc:date>
    <item>
      <title>Splunk Web not accessible via https</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Web-not-accessible-via-https/m-p/479015#M11055</link>
      <description>&lt;P&gt;We had provided created certificates and provided all information in web.conf&lt;BR /&gt;[settings]&lt;BR /&gt;enableSplunkWebSSL = 1&lt;BR /&gt;privKeyPath = /opt/splunk/etc/auth/mycerts/CertAwsDev/private.key&lt;BR /&gt;serverCert = /opt/splunk/etc/auth/mycerts/CertAwsDev/Cert.pem&lt;BR /&gt;httpport = 443&lt;/P&gt;
&lt;P&gt;But we are not getting the 443v port established in the server &lt;BR /&gt;netstat -aen | grep 443&lt;/P&gt;
&lt;P&gt;For this reason it is coming unhealthy (502) in AWS target groups&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 17:38:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Web-not-accessible-via-https/m-p/479015#M11055</guid>
      <dc:creator>abhijitnath89ax</dc:creator>
      <dc:date>2020-06-07T17:38:24Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Web not accessible via https</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Web-not-accessible-via-https/m-p/479016#M11056</link>
      <description>&lt;P&gt;Does the splunkd process listen on port 443? You haven't provided the output of netstat command.&lt;/P&gt;

&lt;P&gt;If splunkd is listening on the port then check firewall (network and local).&lt;/P&gt;

&lt;P&gt;Let me know how it went&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 07:48:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Web-not-accessible-via-https/m-p/479016#M11056</guid>
      <dc:creator>PavelP</dc:creator>
      <dc:date>2020-04-22T07:48:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Web not accessible via https</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Web-not-accessible-via-https/m-p/479017#M11057</link>
      <description>&lt;P&gt;Are you running splunk with root user ? On Linux only root can use port &amp;lt; 1024.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 08:18:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Web-not-accessible-via-https/m-p/479017#M11057</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2020-04-22T08:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Web not accessible via https</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Web-not-accessible-via-https/m-p/479018#M11058</link>
      <description>&lt;P&gt;I am running splunk with root user&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 08:50:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Web-not-accessible-via-https/m-p/479018#M11058</guid>
      <dc:creator>abhijitnath89ax</dc:creator>
      <dc:date>2020-04-22T08:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Web not accessible via https</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Web-not-accessible-via-https/m-p/479019#M11059</link>
      <description>&lt;P&gt;Below is the output of netstat command&lt;/P&gt;

&lt;P&gt;netstat -aen | grep 443&lt;BR /&gt;
tcp        0      0 0.0.0.0:443             0.0.0.0:*               LISTEN      0          9944802&lt;BR /&gt;
tcp        0      0 10.x.x.101:37272     54.x.x.173:443      ESTABLISHED 0          10220872&lt;BR /&gt;
tcp        0      0 10.x.x.101:59914     54.x.x.213:443       TIME_WAIT   0          0&lt;BR /&gt;
tcp        0      0 10.x.x.101:46116     52.x.x.97:443       ESTABLISHED 0          10220742&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 08:52:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Web-not-accessible-via-https/m-p/479019#M11059</guid>
      <dc:creator>abhijitnath89ax</dc:creator>
      <dc:date>2020-04-22T08:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Web not accessible via https</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Web-not-accessible-via-https/m-p/479020#M11060</link>
      <description>&lt;P&gt;Please provide output of &lt;CODE&gt;ss -nltp | grep 443&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 09:01:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Web-not-accessible-via-https/m-p/479020#M11060</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2020-04-22T09:01:48Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Web not accessible via https</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Web-not-accessible-via-https/m-p/479021#M11061</link>
      <description>&lt;P&gt;Based on output provided by you, your server is listening on port 443 but AWS LB is getting 502 Bad gateway in health check. As I don't have more knowledge on AWS side, I can't help much more but if you are using self signed certificate on splunk server then you might need to add root certificate on AWS LB.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 09:42:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Web-not-accessible-via-https/m-p/479021#M11061</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2020-04-22T09:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Web not accessible via https</title>
      <link>https://community.splunk.com/t5/Security/Splunk-Web-not-accessible-via-https/m-p/479022#M11062</link>
      <description>&lt;P&gt;LISTEN   0         128                 0.0.0.0:443              0.0.0.0:*        users:(("splunkd",pid=20841,fd=112))&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 10:06:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-Web-not-accessible-via-https/m-p/479022#M11062</guid>
      <dc:creator>abhijitnath89ax</dc:creator>
      <dc:date>2020-04-22T10:06:58Z</dc:date>
    </item>
  </channel>
</rss>

