<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk Tunnel URL/hostname Change in Installation</title>
    <link>https://community.splunk.com/t5/Installation/Splunk-Tunnel-URL-hostname-Change/m-p/533619#M7008</link>
    <description>&lt;P&gt;So i've been using splunk for a while now and it's fine. To access the console, I use an SSH Tunnel porting localhost 9002 to splunk server web console on port 8000. It's been working fine until recently. I think someone had modified the web.conf or installed some splunk app.&lt;/P&gt;&lt;P&gt;I used to be able to go to &lt;A href="https://localhost:9002" target="_blank" rel="noopener"&gt;https://localhost:9002&lt;/A&gt;&amp;nbsp;to access the splunk UI. But now when I go there, the URL changes to &lt;A href="http://127.0.0.1:8000" target="_blank" rel="noopener"&gt;http://127.0.0.1:8000/en-US/&lt;/A&gt;&amp;nbsp;(what it's running on, on the server), how to I stop it from changing the url like this?&lt;/P&gt;</description>
    <pubDate>Fri, 18 Dec 2020 20:49:14 GMT</pubDate>
    <dc:creator>rtvnguyen</dc:creator>
    <dc:date>2020-12-18T20:49:14Z</dc:date>
    <item>
      <title>Splunk Tunnel URL/hostname Change</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Tunnel-URL-hostname-Change/m-p/533619#M7008</link>
      <description>&lt;P&gt;So i've been using splunk for a while now and it's fine. To access the console, I use an SSH Tunnel porting localhost 9002 to splunk server web console on port 8000. It's been working fine until recently. I think someone had modified the web.conf or installed some splunk app.&lt;/P&gt;&lt;P&gt;I used to be able to go to &lt;A href="https://localhost:9002" target="_blank" rel="noopener"&gt;https://localhost:9002&lt;/A&gt;&amp;nbsp;to access the splunk UI. But now when I go there, the URL changes to &lt;A href="http://127.0.0.1:8000" target="_blank" rel="noopener"&gt;http://127.0.0.1:8000/en-US/&lt;/A&gt;&amp;nbsp;(what it's running on, on the server), how to I stop it from changing the url like this?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2020 20:49:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Tunnel-URL-hostname-Change/m-p/533619#M7008</guid>
      <dc:creator>rtvnguyen</dc:creator>
      <dc:date>2020-12-18T20:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Tunnel URL/hostname Change</title>
      <link>https://community.splunk.com/t5/Installation/Splunk-Tunnel-URL-hostname-Change/m-p/533648#M7009</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/229866"&gt;@rtvnguyen&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Splunk web interface uses two HTTP 303 redirects if you point to &lt;A href="http://127.0.0.1:8000" target="_blank"&gt;http://127.0.0.1:8000&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;A href="http://127.0.0.1:8000/en-US" target="_blank"&gt;http://127.0.0.1:8000/en-US&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://127.0.0.1:8000/en-US/account/login?return_to=%2Fen-US%2F" target="_blank"&gt;http://127.0.0.1:8000/en-US/account/login?return_to=%2Fen-US%2F&lt;/A&gt;&lt;/P&gt;&lt;P&gt;These redirects goes HTTPS or HTTP according to Splunk web.conf, ssl enabled or not.&lt;/P&gt;&lt;P&gt;Your Splunk seems not working SSL enabled. That is why redirecting you &lt;A href="http://127.0.0.1:8000/en-US/" target="_blank"&gt;http://127.0.0.1:8000/en-US/&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;You have three options;&lt;/P&gt;&lt;P&gt;1- Point your SSH Tunnel as &lt;A href="http://localhost:9002" target="_blank"&gt;http://localhost:9002&lt;/A&gt;&lt;/P&gt;&lt;P&gt;2- Edit Splunk web.conf to enable SSL and restart.&lt;/P&gt;&lt;P&gt;3- Use direct link&amp;nbsp;&lt;A href="https://localhost:9002/en-US/account/login?return_to=%2Fen-US%2F" target="_blank"&gt;https://localhost:9002/en-US/account/login?return_to=%2Fen-US%2F&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best Regards,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Dec 2020 12:50:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/Splunk-Tunnel-URL-hostname-Change/m-p/533648#M7009</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2020-12-19T12:50:02Z</dc:date>
    </item>
  </channel>
</rss>

