Getting Data In

Splunk DB Connect and reverse proxy

kenmcgarrahan
Explorer

Running Splunk (in trial mode) behind a reverse proxy (wiki.splunk.com/Community:SplunkBehindAProxy) and have a problem with the DB Connect app not using the configured context root for selected actions.

In ${SPLUNK_HOME}/system/local/web.conf:

[settings]
root_endpoint = /splunkv
tools.proxy.on = True

In the DB Connect configuration in the web console, the URL associated with the 'Database Connections in Splunk Manager' button lacks the '/splunkv'/ context. A 'hover' over indicates the URL is '//myhost/manager/dbx/dbx/databases', an invalid context which displays a 404 error when clicked. Manually correcting the URL to include the 'splunkv' context ('//myhost/splunkv/manager/dbx/dbx/databases') displays the page correctly and allows interaction with the DB Connect configuration.

Is there a corresponding DB Connect proxy setting which corrects this error? Is there a general solution which ensures adherence to the root_endpoint value in web.conf?

0 Karma

araitz
Splunk Employee
Splunk Employee

Yes, there are a few places we've recently identified that do not respect custom root endpoints. There aren't any quick workarounds available yet.

Would it be possible for you to open a support case so we can notify you when there is a fix available? I'll try to remember to update here as well.

araitz
Splunk Employee
Splunk Employee

Sounds good, appreciate it. If I can get a workaround or provide an update here, I will do so.

0 Karma

kenmcgarrahan
Explorer

No valid support contract (yet), so opening a support case isn't possible.

When production licenses are procured, I can add the support case.

0 Karma
Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...