Hi Team,
I am currently using a trial version of Splunk cloud and trying to ingest data from another third-party tool using an HTTP event collector.
This is the endpoint in which I get to post the data using webhooks.
https://inputs.prd-p-g7x4n.splunkcloud.com:8088/services/collector.
The tool which actually sends the webhook data to this endpoint is actually detecting certificate issues for the Splunk endpoint with the following error.
A certificate CN name does not match the passed value.
I do not have an option to bypass these SSL certificate checks.
Can someone let me know how to solve this issue?
Not sure why the certificates are not maintained on the Splunk side as well.
I have also attached screenshots for the SSL checks done from publicly available sites.
Please let me know If need any more information from my side.
Thanks,
Rakesh R
Hi,
Unfortunately there is a limited control over Splunk Cloud free instance with regards to SSL. Free instance use wildcard SSL Cert which your tool do not like it and HEC GlobalSettings disabled too where one can disable HTTPS.
Instead of Splunk> Cloud you can try installing Splunk Enterprise single instance in your local/free AWS tier account and try with HTTP.
------------------------------------
Please upvote if it helps!
Is there any way to get a working trial for Splunk Cloud?
AWS is not a trial but a purchase.
I already have Enterprise working. So using Enterprise instead invalidates the idea of testdriving Cloud.
It looks like most security minded products won't accept to send events to Splunk Cloud Trial because of invalid cert. Browser and curl -k work, but how about real Events?
I see this same issue pop up in a lot of questions(invalid cert/CN), never to be answered. Or maybe I am not searching the community properly.