<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Saved searches issue with SSO in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Saved-searches-issue-with-SSO/m-p/22787#M3971</link>
    <description>&lt;P&gt;No, I did not. That document says to only add anything if the proxy is hosting splunk on non root uri:&lt;/P&gt;

&lt;P&gt;If you host Splunk Web behind a proxy that does not place Splunk Web at the proxy's root, you may also need to configure the root_endpoint setting in $SPLUNK_HOME/etc/system/local/web.conf.&lt;/P&gt;

&lt;P&gt;What should I put in web.conf exactly, regarding the URIs?&lt;/P&gt;</description>
    <pubDate>Mon, 28 Sep 2020 12:44:37 GMT</pubDate>
    <dc:creator>lrhazi</dc:creator>
    <dc:date>2020-09-28T12:44:37Z</dc:date>
    <item>
      <title>Saved searches issue with SSO</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Saved-searches-issue-with-SSO/m-p/22782#M3966</link>
      <description>&lt;P&gt;With all saved searches, I get this error when I try to run them:&lt;/P&gt;

&lt;P&gt;The saved search &lt;CODE&gt;"%2FservicesNS%2Fnobody%2Fsearch%2Fsaved%2Fsearches%2FErrors%2520in%2520the%2520last%252024%2520hours" could not be found.&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;am using Splunk 5.0&lt;/P&gt;

&lt;P&gt;Also, when I first create a search, the popup wizard give this error:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;500 Internal Server Error

Return to Splunk home page

ResourceNotFound: [HTTP 404] &lt;A href="https://127.0.0.1:8089/services/%2FservicesNS%2Fml623%2Fsearch%2Fsaved%2Fsearches%2Ftest03" target="test_blank"&gt;https://127.0.0.1:8089/services/%2FservicesNS%2Fml623%2Fsearch%2Fsaved%2Fsearches%2Ftest03&lt;/A&gt;; []
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The search is effectivily created, as I can see iet later on in the drop down and in Saved Searches....&lt;/P&gt;

&lt;P&gt;am thinking these two issues are related...&lt;BR /&gt;
I must be missing some setting that helps the GUI know it is now running behind a proxy.&lt;BR /&gt;
But which setting is it?&lt;/P&gt;</description>
      <pubDate>Sun, 04 Nov 2012 18:11:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Saved-searches-issue-with-SSO/m-p/22782#M3966</guid>
      <dc:creator>lrhazi</dc:creator>
      <dc:date>2012-11-04T18:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: Saved searches issue with SSO</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Saved-searches-issue-with-SSO/m-p/22783#M3967</link>
      <description>&lt;P&gt;It may be easier to advise you if you indicated what configuration you did perform, and how exactly you and your proxy access Splunk.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Nov 2012 02:09:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Saved-searches-issue-with-SSO/m-p/22783#M3967</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2012-11-05T02:09:52Z</dc:date>
    </item>
    <item>
      <title>Re: Saved searches issue with SSO</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Saved-searches-issue-with-SSO/m-p/22784#M3968</link>
      <description>&lt;P&gt;Not sure what you mean by "what configuration you did perform". My proxy is what I believe to be a typical apache proxy config, performing ldap auth and forwarding traffic to localhost:8000 where splunk web is running by default.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Nov 2012 04:44:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Saved-searches-issue-with-SSO/m-p/22784#M3968</guid>
      <dc:creator>lrhazi</dc:creator>
      <dc:date>2012-11-05T04:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: Saved searches issue with SSO</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Saved-searches-issue-with-SSO/m-p/22785#M3969</link>
      <description>&lt;P&gt;So, you did &lt;EM&gt;no&lt;/EM&gt; configuration to tell Splunk that you are behind an SSO proxy.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Nov 2012 04:46:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Saved-searches-issue-with-SSO/m-p/22785#M3969</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2012-11-05T04:46:45Z</dc:date>
    </item>
    <item>
      <title>Re: Saved searches issue with SSO</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Saved-searches-issue-with-SSO/m-p/22786#M3970</link>
      <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Security/ConfigureSplunkSSO"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Security/ConfigureSplunkSSO&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Nov 2012 04:46:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Saved-searches-issue-with-SSO/m-p/22786#M3970</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2012-11-05T04:46:52Z</dc:date>
    </item>
    <item>
      <title>Re: Saved searches issue with SSO</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Saved-searches-issue-with-SSO/m-p/22787#M3971</link>
      <description>&lt;P&gt;No, I did not. That document says to only add anything if the proxy is hosting splunk on non root uri:&lt;/P&gt;

&lt;P&gt;If you host Splunk Web behind a proxy that does not place Splunk Web at the proxy's root, you may also need to configure the root_endpoint setting in $SPLUNK_HOME/etc/system/local/web.conf.&lt;/P&gt;

&lt;P&gt;What should I put in web.conf exactly, regarding the URIs?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:44:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Saved-searches-issue-with-SSO/m-p/22787#M3971</guid>
      <dc:creator>lrhazi</dc:creator>
      <dc:date>2020-09-28T12:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: Saved searches issue with SSO</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Saved-searches-issue-with-SSO/m-p/22788#M3972</link>
      <description>&lt;P&gt;To be clear, I did some configuration, and it is exactly the document you linked. I am sure I missed something though, but what is it?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Nov 2012 05:09:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Saved-searches-issue-with-SSO/m-p/22788#M3972</guid>
      <dc:creator>lrhazi</dc:creator>
      <dc:date>2012-11-05T05:09:03Z</dc:date>
    </item>
    <item>
      <title>Re: Saved searches issue with SSO</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Saved-searches-issue-with-SSO/m-p/22789#M3973</link>
      <description>&lt;P&gt;Support tells me this a bug related to SSL:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;SPL-57518 has been assigned to this&lt;BR /&gt;
issue. It happens because there is&lt;BR /&gt;
wrong uri encoding from splunkweb when&lt;BR /&gt;
using SSL.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 06 Nov 2012 20:12:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Saved-searches-issue-with-SSO/m-p/22789#M3973</guid>
      <dc:creator>lrhazi</dc:creator>
      <dc:date>2012-11-06T20:12:32Z</dc:date>
    </item>
  </channel>
</rss>

