<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Http Event Collector (HEC): SSL Self Signed Certificate Error in Security</title>
    <link>https://community.splunk.com/t5/Security/Http-Event-Collector-HEC-SSL-Self-Signed-Certificate-Error/m-p/683255#M17745</link>
    <description>&lt;P&gt;Can you post the output of this command? (replace with your trial stack's name).&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;openssl s_client -connect prd-p-xxxxx.splunkcloud.com:8088&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;I suspect the cert you'll see returned is from the Splunk internal CA, and that the Splunk Cloud trials are not set up with a signed cert on port 8089.&lt;/P&gt;&lt;P&gt;On a production/paid Splunk Cloud stack you'd send logs to &lt;A href="https://http-inputs-" target="_blank"&gt;https://http-inputs-&lt;/A&gt;&amp;lt;stack_name&amp;gt;&amp;nbsp;.splunkcloud.com on port 443 and I've never seen an issue with certificate validation in those environments (it uses the same cert as the web interface).&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Apr 2024 13:31:00 GMT</pubDate>
    <dc:creator>tkopchak</dc:creator>
    <dc:date>2024-04-04T13:31:00Z</dc:date>
    <item>
      <title>Http Event Collector (HEC): SSL Self Signed Certificate Error</title>
      <link>https://community.splunk.com/t5/Security/Http-Event-Collector-HEC-SSL-Self-Signed-Certificate-Error/m-p/683007#M17739</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi all,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am currently testing the Http Event Collector (HEC) with a Splunk Cloud trial account. All I do is post data to the HEC url, and It works perfectly for a local instance for an Enterprise account at&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A href="http://127.0.0.1:8088/services/collector/event" target="_blank" rel="noopener"&gt;http://127.0.0.1:8088/services/collector/event&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;A solution I saw on the community forum was to disable the SSL validation. However, this isn't the best option to use in production for security reasons. Another Solution I saw was to upload certificates but this option isn't suited for a SaaS solution with many different customers.&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;&lt;BR /&gt;Is it possible to solve this&amp;nbsp;issue in a different way? And I would also like to ask if this problem would persist for normal production client accounts and along with a generic solution for it?&amp;nbsp;&amp;nbsp;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;Curl requests&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;curl https://prd-p-xxxxx.splunkcloud.com:8088/services/collector/event -H "Authorization: Splunk token" -d '{"event": "hello world"}'&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Curl Response&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;curl: (60) SSL certificate problem: self signed certificate in certificate chain
More details here: https://curl.se/docs/sslcerts.html
curl failed to verify the legitimacy of the server and therefore could not
establish a secure connection to it. To learn more about this situation and how to fix it, please visit the web page mentioned above.&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Thank you for your time and assistance in addressing these inquiries.&amp;nbsp;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 03 Apr 2024 10:46:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Http-Event-Collector-HEC-SSL-Self-Signed-Certificate-Error/m-p/683007#M17739</guid>
      <dc:creator>marketplace</dc:creator>
      <dc:date>2024-04-03T10:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: Http Event Collector (HEC): SSL Self Signed Certificate Error</title>
      <link>https://community.splunk.com/t5/Security/Http-Event-Collector-HEC-SSL-Self-Signed-Certificate-Error/m-p/683255#M17745</link>
      <description>&lt;P&gt;Can you post the output of this command? (replace with your trial stack's name).&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;openssl s_client -connect prd-p-xxxxx.splunkcloud.com:8088&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;I suspect the cert you'll see returned is from the Splunk internal CA, and that the Splunk Cloud trials are not set up with a signed cert on port 8089.&lt;/P&gt;&lt;P&gt;On a production/paid Splunk Cloud stack you'd send logs to &lt;A href="https://http-inputs-" target="_blank"&gt;https://http-inputs-&lt;/A&gt;&amp;lt;stack_name&amp;gt;&amp;nbsp;.splunkcloud.com on port 443 and I've never seen an issue with certificate validation in those environments (it uses the same cert as the web interface).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 13:31:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Http-Event-Collector-HEC-SSL-Self-Signed-Certificate-Error/m-p/683255#M17745</guid>
      <dc:creator>tkopchak</dc:creator>
      <dc:date>2024-04-04T13:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: Http Event Collector (HEC): SSL Self Signed Certificate Error</title>
      <link>https://community.splunk.com/t5/Security/Http-Event-Collector-HEC-SSL-Self-Signed-Certificate-Error/m-p/683584#M17756</link>
      <description>&lt;P&gt;Here is the response:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;CONNECTED(00000005)
depth=1 C = US, ST = CA, L = San Francisco, O = Splunk, CN = SplunkCommonCA, emailAddress = support@splunk.com
verify error:num=19:self signed certificate in certificate chain
verify return:0
write W BLOCK
Certificate chain
 0 s:/CN=SplunkServerDefaultCert/O=SplunkUser
   i:/C=US/ST=CA/L=San Francisco/O=Splunk/CN=SplunkCommonCA/emailAddress=support@splunk.com
 1 s:/C=US/ST=CA/L=San Francisco/O=Splunk/CN=SplunkCommonCA/emailAddress=support@splunk.com
   i:/C=US/ST=CA/L=San Francisco/O=Splunk/CN=SplunkCommonCA/emailAddress=support@splunk.com&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, the certs are from Splunk.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 11:18:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Http-Event-Collector-HEC-SSL-Self-Signed-Certificate-Error/m-p/683584#M17756</guid>
      <dc:creator>marketplace</dc:creator>
      <dc:date>2024-04-08T11:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: Http Event Collector (HEC): SSL Self Signed Certificate Error</title>
      <link>https://community.splunk.com/t5/Security/Http-Event-Collector-HEC-SSL-Self-Signed-Certificate-Error/m-p/683590#M17757</link>
      <description>&lt;P&gt;Yep, that's the default self-signed cert that comes with Splunk like I suspected.&amp;nbsp; There's likely no way to fix that on a Cloud trial (and you'll have to disable SSL validation for testing) but you won't have to do that on a production Splunk Cloud stack.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Apr 2024 12:32:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Http-Event-Collector-HEC-SSL-Self-Signed-Certificate-Error/m-p/683590#M17757</guid>
      <dc:creator>tkopchak</dc:creator>
      <dc:date>2024-04-08T12:32:48Z</dc:date>
    </item>
    <item>
      <title>Re: Http Event Collector (HEC): SSL Self Signed Certificate Error</title>
      <link>https://community.splunk.com/t5/Security/Http-Event-Collector-HEC-SSL-Self-Signed-Certificate-Error/m-p/691138#M17941</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/90407"&gt;@tkopchak&lt;/a&gt;&amp;nbsp;I cannot disable SSL in global settings because it's grayed out. do you have anything else I can try?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2024 00:41:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Http-Event-Collector-HEC-SSL-Self-Signed-Certificate-Error/m-p/691138#M17941</guid>
      <dc:creator>johnC</dc:creator>
      <dc:date>2024-06-20T00:41:19Z</dc:date>
    </item>
  </channel>
</rss>

