<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk ES: Failed to update finding: cannot redirect an already redirected call in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Failed-to-update-finding-cannot-redirect-an-already/m-p/741559#M12410</link>
    <description>&lt;P&gt;Greetings.&lt;/P&gt;&lt;P&gt;We are currently using Splunk ES (on-prem) 7.3.3, I updated Splunk to version 9.4.1. Since the upgrade we're unable to edit ES findings. For instance If i try to edit a a finding so it can be reassigned to someone, or closed. I receive the following error pop-up:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;"Failure&lt;BR /&gt;Failed to update finding: Cannot redirect an already redirected call"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I haven't been able to locate any resources that maybe able to help point in the right directions. Any help would be appreciated.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Mar 2025 11:49:05 GMT</pubDate>
    <dc:creator>MU2DOD</dc:creator>
    <dc:date>2025-03-12T11:49:05Z</dc:date>
    <item>
      <title>Splunk ES: Failed to update finding: cannot redirect an already redirected call</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Failed-to-update-finding-cannot-redirect-an-already/m-p/741559#M12410</link>
      <description>&lt;P&gt;Greetings.&lt;/P&gt;&lt;P&gt;We are currently using Splunk ES (on-prem) 7.3.3, I updated Splunk to version 9.4.1. Since the upgrade we're unable to edit ES findings. For instance If i try to edit a a finding so it can be reassigned to someone, or closed. I receive the following error pop-up:&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;"Failure&lt;BR /&gt;Failed to update finding: Cannot redirect an already redirected call"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I haven't been able to locate any resources that maybe able to help point in the right directions. Any help would be appreciated.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2025 11:49:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Failed-to-update-finding-cannot-redirect-an-already/m-p/741559#M12410</guid>
      <dc:creator>MU2DOD</dc:creator>
      <dc:date>2025-03-12T11:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES: Failed to update finding: cannot redirect an already redirected call</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Failed-to-update-finding-cannot-redirect-an-already/m-p/741579#M12411</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/269872"&gt;@MU2DOD&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It looks like you're experiencing an issue which first started in ES8. Check out&amp;nbsp;&lt;A href="https://splunk.my.site.com/customer/s/article/Mission-control-8-0-fails-to-assign" target="_blank" rel="noopener"&gt;https://splunk.my.site.com/customer/s/article/Mission-control-8-0-fails-to-assign&lt;/A&gt;&amp;nbsp;for more detailed info, however I believe the following should fix the issue for you:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;ensure that FQDN instead of ServerName is set in server.conf in the whole environment&lt;UL&gt;&lt;LI&gt;do that step if splunkd logs, reference hostnames (names without domain names, meaning non-FQDN) over HTTPS&lt;/LI&gt;&lt;LI&gt;set sslVerifyServerCert and sslVerifyServerName to true in all instances&lt;/LI&gt;&lt;LI&gt;then restart the whole Splunk Environment where changes have been made&lt;/LI&gt;&lt;LI&gt;push the bundle from the deployer to the SHC members&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Once that is done, then in Mission Control, manually add Investigation Types (which previously wasn't working)&lt;UL&gt;&lt;LI&gt;then set the newly added type as the default&lt;/LI&gt;&lt;LI&gt;then editing notable events, adding custom fields, and other should work&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Please let me know how you get on and consider adding karma to this or any other answer if it has helped.&lt;BR /&gt;Regards&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2025 12:54:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Failed-to-update-finding-cannot-redirect-an-already/m-p/741579#M12411</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2025-03-12T12:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES: Failed to update finding: cannot redirect an already redirected call</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Failed-to-update-finding-cannot-redirect-an-already/m-p/741602#M12412</link>
      <description>&lt;P&gt;&amp;lt;removed&amp;gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2025 15:38:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Failed-to-update-finding-cannot-redirect-an-already/m-p/741602#M12412</guid>
      <dc:creator>MU2DOD</dc:creator>
      <dc:date>2025-03-12T15:38:54Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk ES: Failed to update finding: cannot redirect an already redirected call</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Failed-to-update-finding-cannot-redirect-an-already/m-p/741603#M12413</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/170906" target="_blank"&gt;@livehybrid&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;For "&lt;/SPAN&gt;&lt;SPAN&gt;set sslVerifyServerCert and sslVerifyServerName," there are 5 stanzas in server.conf that has these keys available. Do I need set these to true for all 5?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Mar 2025 15:38:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Splunk-ES-Failed-to-update-finding-cannot-redirect-an-already/m-p/741603#M12413</guid>
      <dc:creator>MU2DOD</dc:creator>
      <dc:date>2025-03-12T15:38:15Z</dc:date>
    </item>
  </channel>
</rss>

