Getting Data In

Issues with HTTP Event Collector endpoint URL.

rakeshkp
Loves-to-Learn Everything

Hi Team,

I am currently using a trial version of Splunk cloud and trying to ingest data from another third-party tool using an HTTP event collector. 
This is the endpoint in which I get to post the data using webhooks.
https://inputs.prd-p-g7x4n.splunkcloud.com:8088/services/collector
The tool which actually sends the webhook data to this endpoint is actually detecting certificate issues for the Splunk endpoint with the following error.

A certificate CN name does not match the passed value.

I do not have an option to bypass these SSL certificate checks.  

Can someone let me know how to solve this issue?
Not sure why the certificates are not maintained on the Splunk side as well.

I have also attached screenshots for the SSL checks done from publicly available sites.

ssl errors 3.png

Please let me know If need any more information from my side.

Thanks,
Rakesh R

Labels (1)
0 Karma

venkatasri
SplunkTrust
SplunkTrust

Hi,

Unfortunately there is a limited control over Splunk Cloud free instance with regards to SSL. Free instance use wildcard SSL Cert which your tool do not like it and HEC GlobalSettings disabled too where one can disable HTTPS.

Instead of Splunk> Cloud you can try installing Splunk Enterprise single instance in your local/free AWS tier account and try with HTTP.

------------------------------------

Please upvote if it helps!

0 Karma

mbluteau44
New Member

Is there any way to get a working trial for Splunk Cloud?

 

AWS is not a trial but a purchase.

 

I already have Enterprise working.  So using Enterprise instead invalidates the idea of testdriving Cloud.

 

It looks like most security minded products won't accept to send events to Splunk Cloud Trial because of invalid cert.  Browser and curl -k work, but how about real Events?

 

I see this same issue pop up in a lot of questions(invalid cert/CN), never to be answered.  Or maybe I am not searching the community properly.

0 Karma
Get Updates on the Splunk Community!

OpenTelemetry for Legacy Apps? Yes, You Can!

This article is a follow-up to my previous article posted on the OpenTelemetry Blog, "Your Critical Legacy App ...

UCC Framework: Discover Developer Toolkit for Building Technology Add-ons

The Next-Gen Toolkit for Splunk Technology Add-on Development The Universal Configuration Console (UCC) ...

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...