All Apps and Add-ons

Can't save Wazuh API settings

dfumarola
New Member

Hi @wazuh community,

I'm trying to setup the Wazuh App and I'm facing an issue where I can't save my API settings via the UI.

I'm using the latest Wazuh App for our Splunk build, wazuhapp-splunk-3.11.4_8.0.1, and when I try to save the conf I get a 500 error locally when this check is run (hostname and password are omitted):

(from web_access.log)

/en-US/custom/SplunkAppForWazuh//manager/check_connection?ip=hxxps://X.Y.Z.T&port=55000&user=api_user&pass=********  HTTP/1.1" 500

(from web_service.log)

../../../var/log/splunk/web_service.log:2020-06-12 06:28:43,613 INFO [5ee358db8f7fdbf705c710] error:333 - GET /en-US/custom/SplunkAppForWazuh/manager/check_connection 127.0.0.1 8065
../../../var/log/splunk/web_service.log: File "<string>", line 351, in check_connection
../../../var/log/splunk/web_service.log: File "</opt/splunk/lib/python3.7/site-packages/decorator.py:decorator-gen-2800>", line 2, in check_connection
../../../var/log/splunk/web_service.log: File "</opt/splunk/lib/python3.7/site-packages/decorator.py:decorator-gen-2798>", line 2, in check_connection
../../../var/log/splunk/web_service.log: File "</opt/splunk/lib/python3.7/site-packages/decorator.py:decorator-gen-2797>", line 2, in check_connection
../../../var/log/splunk/web_service.log: File "</opt/splunk/lib/python3.7/site-packages/decorator.py:decorator-gen-2796>", line 2, in check_connection

My splunk instace run as a non-root.

I would appreciate any help provided

Labels (2)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...