<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk with reverse proxy. After Authenticating, not able to see logs (Search could not found) in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-with-reverse-proxy-After-Authenticating-not-able-to-see/m-p/467924#M15156</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;We'v implemented reverse proxy in our environment for authentication. We're able to login thorough our card but after logging in. &lt;/P&gt;

&lt;P&gt;We could see all the dashboards but the saved searches and queries on dashboard cannot run.&lt;/P&gt;

&lt;P&gt;It shows error as following "Search could not start/found&lt;/P&gt;

&lt;P&gt;Following is the change that we've done in web.conf&lt;BR /&gt;
root_endpoint = /&lt;BR /&gt;
SSOMode = strict&lt;BR /&gt;
trustedIP = proxy IP&lt;BR /&gt;
remoteUser = user on proxy server&lt;BR /&gt;
tools.proxy.on = false&lt;BR /&gt;
enableWebDebug=true"&lt;/P&gt;

&lt;P&gt;Could you please look into this and advice what could be the reason ?&lt;/P&gt;</description>
    <pubDate>Thu, 06 Feb 2020 06:52:28 GMT</pubDate>
    <dc:creator>rupeshn</dc:creator>
    <dc:date>2020-02-06T06:52:28Z</dc:date>
    <item>
      <title>Splunk with reverse proxy. After Authenticating, not able to see logs (Search could not found)</title>
      <link>https://community.splunk.com/t5/Security/Splunk-with-reverse-proxy-After-Authenticating-not-able-to-see/m-p/467924#M15156</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;We'v implemented reverse proxy in our environment for authentication. We're able to login thorough our card but after logging in. &lt;/P&gt;

&lt;P&gt;We could see all the dashboards but the saved searches and queries on dashboard cannot run.&lt;/P&gt;

&lt;P&gt;It shows error as following "Search could not start/found&lt;/P&gt;

&lt;P&gt;Following is the change that we've done in web.conf&lt;BR /&gt;
root_endpoint = /&lt;BR /&gt;
SSOMode = strict&lt;BR /&gt;
trustedIP = proxy IP&lt;BR /&gt;
remoteUser = user on proxy server&lt;BR /&gt;
tools.proxy.on = false&lt;BR /&gt;
enableWebDebug=true"&lt;/P&gt;

&lt;P&gt;Could you please look into this and advice what could be the reason ?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 06:52:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-with-reverse-proxy-After-Authenticating-not-able-to-see/m-p/467924#M15156</guid>
      <dc:creator>rupeshn</dc:creator>
      <dc:date>2020-02-06T06:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk with reverse proxy. After Authenticating, not able to see logs (Search could not found)</title>
      <link>https://community.splunk.com/t5/Security/Splunk-with-reverse-proxy-After-Authenticating-not-able-to-see/m-p/467925#M15157</link>
      <description>&lt;P&gt;What software/hardware are you using as a reverse proxy? And how is that set up?&lt;/P&gt;

&lt;P&gt;Any info on what is inside the following two files could also be helpful.&lt;BR /&gt;
$SPLUNK_HOME/var/log/splunk/web_access.log&lt;BR /&gt;
$SPLUNK_HOME/var/log/splunk/web_service.log&lt;/P&gt;

&lt;P&gt;Also the logfiles for the reverse proxy could be helpful.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:07:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-with-reverse-proxy-After-Authenticating-not-able-to-see/m-p/467925#M15157</guid>
      <dc:creator>uwehermann</dc:creator>
      <dc:date>2020-09-30T04:07:48Z</dc:date>
    </item>
  </channel>
</rss>

