Getting Data In

Issues with HTTP Event Collector endpoint URL.

rakeshkp
Loves-to-Learn Everything

Hi Team,

I am currently using a trial version of Splunk cloud and trying to ingest data from another third-party tool using an HTTP event collector. 
This is the endpoint in which I get to post the data using webhooks.
https://inputs.prd-p-g7x4n.splunkcloud.com:8088/services/collector
The tool which actually sends the webhook data to this endpoint is actually detecting certificate issues for the Splunk endpoint with the following error.

A certificate CN name does not match the passed value.

I do not have an option to bypass these SSL certificate checks.  

Can someone let me know how to solve this issue?
Not sure why the certificates are not maintained on the Splunk side as well.

I have also attached screenshots for the SSL checks done from publicly available sites.

ssl errors 3.png

Please let me know If need any more information from my side.

Thanks,
Rakesh R

Labels (1)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi,

Unfortunately there is a limited control over Splunk Cloud free instance with regards to SSL. Free instance use wildcard SSL Cert which your tool do not like it and HEC GlobalSettings disabled too where one can disable HTTPS.

Instead of Splunk> Cloud you can try installing Splunk Enterprise single instance in your local/free AWS tier account and try with HTTP.

------------------------------------

Please upvote if it helps!

0 Karma

mbluteau44
New Member

Is there any way to get a working trial for Splunk Cloud?

 

AWS is not a trial but a purchase.

 

I already have Enterprise working.  So using Enterprise instead invalidates the idea of testdriving Cloud.

 

It looks like most security minded products won't accept to send events to Splunk Cloud Trial because of invalid cert.  Browser and curl -k work, but how about real Events?

 

I see this same issue pop up in a lot of questions(invalid cert/CN), never to be answered.  Or maybe I am not searching the community properly.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...