Deployment Architecture

problem in removing "Continue with external content?" warning

dorHerbesman
Path Finder

i have a problem with the mention warning on my search head:(attached photo)

dorHerbesman_0-1733928036973.png

i tried following the guide here:
Configure Dashboards Trusted Domains List - Splunk Documentation
and run :
curl -k -u admin:$password$ https://mysplunk.com:8000/servicesNS/nobody/system/web-features/feature:dashboards_csp -d dashboards_trusted_domain.exampleLabel=http://jenkins/
and got: 
curl: (56) Received HTTP code 403 from proxy after CONNECT
i tried running it on the splunk master and on some of the search heads and it didn't work.
also tried 
editting :
/etc/system/local/web.conf with:
[settings]
dashboards_trusted_domains = http://jenkins https://jenkins
and still the same error

 

what am i doing wrong?

thanks in advanced to helpers!

Labels (1)
Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @dorHerbesman ,

at first, you must edit the web-features.conf file not web.conf.

Then you should try a value for each row:

[feature:dashboards_csp]
enable_dashboards_external_content_restriction = true
enable_dashboards_redirection_restriction = true
dashboards_trusted_domain.endpoint1 = http://jenkins
dashboards_trusted_domain.endpoint2 = https://jenkins

as you can read at https://docs.splunk.com/Documentation/Splunk/9.3.2/Admin/Web-featuresconf#web-features.conf.example

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @dorHerbesman ,

at first, you must edit the web-features.conf file not web.conf.

Then you should try a value for each row:

[feature:dashboards_csp]
enable_dashboards_external_content_restriction = true
enable_dashboards_redirection_restriction = true
dashboards_trusted_domain.endpoint1 = http://jenkins
dashboards_trusted_domain.endpoint2 = https://jenkins

as you can read at https://docs.splunk.com/Documentation/Splunk/9.3.2/Admin/Web-featuresconf#web-features.conf.example

Ciao.

Giuseppe

dorHerbesman
Path Finder
i have tried pasting your code into /opt/splunk/etc/system/local/web.features.conf of my splunk master instance and restarting it (including rolling-restart) and no luck. maybe i should put it somewhere in my shcluster/apps? any other suggestion?
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @dorHerbesman ,

beware web-features.conf not web.features.conf, but maybe it's a mistyping.

Anyway, what do you mean with Splunk master instance?

you have to do this on the Search Heads, not on other instances.

Ciao.

Giuseppe

 

0 Karma

dorHerbesman
Path Finder

i did it on each search head separately and it worked!

too bad there's no way to do it from the master and deploy it them but atleast it works.

thanks for the help!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...