After editing the web.conf to add root_endpoint to settings stanza, why is there a lot of HTTP redirection?



I'm running Splunk version 6.5.3 and is looking to change my Splunk web URL to from http://:8000 to http://:8000/splunk, so I modify the web.conf file under /etc/system/local and added root_endpoint to settings stanza:

root_endpoint = /splunk

However after restarting Splunk service, my browser will redirect http://:8000/splunk to http://:8000/en-US/splunk/en-US. When I checked the splunkd_ui_access.log, it seems like there is a number of redirection of my http request. - - [13/May/2017:04:10:48.785 +0800] "GET /splunk HTTP/1.1" 303 345 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; rv:11.0) like Gecko" - - 0ms - - [13/May/2017:04:10:48.786 +0800] "GET /splunk/en-US/ HTTP/1.1" 303 126 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; rv:11.0) like Gecko" - - 73ms - - [13/May/2017:04:10:48.862 +0800] "GET /en-US/splunk/en-US HTTP/1.1" 404 1350 "-" "Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; rv:11.0) like Gecko" - - 10ms

Splunk Employee
Splunk Employee

Since it appears there's no obvious solution, I would recommend opening a support ticket. This may need a couple of conversations to truly understand what's going on.

0 Karma


I have a similar issue:

With a dedicated Webservice Loadbalancing and SSL Encryption Infrastructure I need to put an empty .html probe to a specific folder (i.e. /lbprobe/lbtest.html).
By adding to the local web.conf "testing" section, I managed to provide the file for a moment:

testing_endpoint = /lbprobe
testing_dir = share/splunk/lbprobe

Putting an empty file with the name "lbtest.html" to folder ./share/splunk/lbprobe/lbtest.html will make the folder and the file accessible with a browser client, as the browser will do the 303-redirection to a subfolder (i.e. /en-US/ or /de-DE/).

Trying to access via telnet or the proxied URL will return in a failure due to the 303 (moved temporary) failure.

0 Karma

New Member

I am facing same issue

0 Karma

New Member

I have the same issue in Splunk 7.x
Is there a solution available?

0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...