<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't connect Splunk SOAR to Splunk Enterprise Security in Splunk SOAR</title>
    <link>https://community.splunk.com/t5/Splunk-SOAR/Can-t-connect-Splunk-SOAR-to-Splunk-Enterprise-Security/m-p/748679#M1750</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263167"&gt;@Alan_Chan&lt;/a&gt;&amp;nbsp;- Are you sure your Splunk port is 8443??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jun 2025 09:31:44 GMT</pubDate>
    <dc:creator>VatsalJagani</dc:creator>
    <dc:date>2025-06-25T09:31:44Z</dc:date>
    <item>
      <title>Can't connect Splunk SOAR to Splunk Enterprise Security</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Can-t-connect-Splunk-SOAR-to-Splunk-Enterprise-Security/m-p/748618#M1749</link>
      <description>&lt;P&gt;I am using &lt;STRONG&gt;Enterprise 9.3.2&lt;/STRONG&gt;, &lt;STRONG&gt;ES 8.1.0&lt;/STRONG&gt;, and &lt;STRONG&gt;SOAR 6.4.1&lt;/STRONG&gt; to test the pairing function. Both devices are on-premises and in the same subnet, with no network issues between them. However, when I try to use the pairing function in ES, the following error message appears:&lt;BR /&gt;&lt;STRONG&gt;"Cannot connect to SOAR. Check that the ES IP address is included on the SOAR stack allow list."&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;When I check the internal log, it shows the following error:&lt;BR /&gt;&lt;STRONG&gt;"Unexpected error when attempting pairing: HTTPSConnectionPool(host='xxx.xxx.xxx.xxx', port=8443): Max retries exceeded with URL: /rest/version (Caused by SSLError(SSLError(1, '[SSL: SSLV3_ALERT_HANDSHAKE_FAILURE] sslv3 alert handshake failure (_ssl.c:1143)')))".&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Does anyone have any ideas on how to resolve this?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 16:36:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Can-t-connect-Splunk-SOAR-to-Splunk-Enterprise-Security/m-p/748618#M1749</guid>
      <dc:creator>Alan_Chan</dc:creator>
      <dc:date>2025-06-24T16:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: Can't connect Splunk SOAR to Splunk Enterprise Security</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Can-t-connect-Splunk-SOAR-to-Splunk-Enterprise-Security/m-p/748679#M1750</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263167"&gt;@Alan_Chan&lt;/a&gt;&amp;nbsp;- Are you sure your Splunk port is 8443??&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jun 2025 09:31:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Can-t-connect-Splunk-SOAR-to-Splunk-Enterprise-Security/m-p/748679#M1750</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2025-06-25T09:31:44Z</dc:date>
    </item>
    <item>
      <title>Re: Can't connect Splunk SOAR to Splunk Enterprise Security</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Can-t-connect-Splunk-SOAR-to-Splunk-Enterprise-Security/m-p/748762#M1751</link>
      <description>&lt;P&gt;Splunk ES using 8000 port while SOAR using 8443 port&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 01:27:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Can-t-connect-Splunk-SOAR-to-Splunk-Enterprise-Security/m-p/748762#M1751</guid>
      <dc:creator>Alan_Chan</dc:creator>
      <dc:date>2025-06-26T01:27:07Z</dc:date>
    </item>
    <item>
      <title>Re: Can't connect Splunk SOAR to Splunk Enterprise Security</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Can-t-connect-Splunk-SOAR-to-Splunk-Enterprise-Security/m-p/748766#M1752</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263167"&gt;@Alan_Chan&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is your ES IP added to your SOAR allow list?&lt;BR /&gt;Check connection before pairing - Confirm that Enterprise Security can initiate a TCP connection for REST calls to the SOAR port&lt;BR /&gt;Also error highlights SSL handshake failure-Are you using self signed or valid CA certificate in the SOAR?&lt;BR /&gt;Also note that, Splunk Enterprise Security requires a valid SSL certificate to communicate with Splunk SOAR&lt;/P&gt;&lt;P&gt;Ref:#&lt;A href="https://help.splunk.com/en/splunk-enterprise-security-8/administer/8.0/configuration-and-settings/pair-splunk-enterprise-security-with-splunk-soar" target="_blank"&gt;https://help.splunk.com/en/splunk-enterprise-security-8/administer/8.0/configuration-and-settings/pair-splunk-enterprise-security-with-splunk-soar&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Prewin&lt;BR /&gt;Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 05:16:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Can-t-connect-Splunk-SOAR-to-Splunk-Enterprise-Security/m-p/748766#M1752</guid>
      <dc:creator>PrewinThomas</dc:creator>
      <dc:date>2025-06-26T05:16:03Z</dc:date>
    </item>
    <item>
      <title>Re: Can't connect Splunk SOAR to Splunk Enterprise Security</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Can-t-connect-Splunk-SOAR-to-Splunk-Enterprise-Security/m-p/748774#M1753</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263167"&gt;@Alan_Chan&lt;/a&gt;&amp;nbsp;- Here is what got to understand:&lt;/P&gt;&lt;P&gt;* You are using SOAR on 8443 port.&lt;/P&gt;&lt;P&gt;* You are trying to connect SOAR from Splunk ES as per this -&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/6.4.1/introduction-to-splunk-soar-on-premises/pair-splunk-soar-on-premises-with-splunk-enterprise-security-on-premises" target="_blank"&gt;https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/6.4.1/introduction-to-splunk-soar-on-premises/pair-splunk-soar-on-premises-with-splunk-enterprise-security-on-premises&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this is the case and if:&lt;/P&gt;&lt;P&gt;* you are entering the IP &amp;amp; credentials correct&lt;/P&gt;&lt;P&gt;* and there is no connectivity issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then it is most likely SSL certificate validation issue. And your error also suggests the same thing.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="VatsalJagani_0-1750928546326.png" style="width: 775px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/39502i393D44706426D74F/image-dimensions/775x31?v=v2" width="775" height="31" role="button" title="VatsalJagani_0-1750928546326.png" alt="VatsalJagani_0-1750928546326.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can follow the document to fix it -&amp;nbsp;&lt;A href="https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/6.4.1/manage-splunk-soar-on-premises-certificate-store/update-or-renew-ssl-certificates-for-nginx-rabbitmq-or-consul#f311597b_e8dd_40f2_9844_a62f90ffc64c__Updating_the_SSL_certificates" target="_blank"&gt;https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/6.4.1/manage-splunk-soar-on-premises-certificate-store/update-or-renew-ssl-certificates-for-nginx-rabbitmq-or-consul#f311597b_e8dd_40f2_9844_a62f90ffc64c__Updating_the_SSL_certificates&lt;/A&gt;&lt;/P&gt;&lt;P&gt;* Please kindly understand SSL certificates well before you apply this on Production to avoid any issues.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I hope this helps!!! Kindly upvote if it does!!!&lt;/P&gt;</description>
      <pubDate>Thu, 26 Jun 2025 09:03:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Can-t-connect-Splunk-SOAR-to-Splunk-Enterprise-Security/m-p/748774#M1753</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2025-06-26T09:03:53Z</dc:date>
    </item>
    <item>
      <title>Re: Can't connect Splunk SOAR to Splunk Enterprise Security</title>
      <link>https://community.splunk.com/t5/Splunk-SOAR/Can-t-connect-Splunk-SOAR-to-Splunk-Enterprise-Security/m-p/753538#M1792</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/263167"&gt;@Alan_Chan&lt;/a&gt;&amp;nbsp;, did you resolved problem? I have same problem, tried to disable https verification but still have&amp;nbsp;&lt;STRONG&gt;sslv3 alert handshake failure&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Sep 2025 08:03:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-SOAR/Can-t-connect-Splunk-SOAR-to-Splunk-Enterprise-Security/m-p/753538#M1792</guid>
      <dc:creator>simo1</dc:creator>
      <dc:date>2025-09-24T08:03:31Z</dc:date>
    </item>
  </channel>
</rss>

