Security

Can Splunk be served from a different endpoint?

sh4kesbeer
Explorer

I am currently trying to let splunk run behind a reverse proxy so that there can be multiple web-services on the same domain.
The goal is to run splunk from e.g.:

https://example.com:9000/abc/

so that this maps to e.g.

http://some-local-machine:8000/ 

where splunk is running at port 8000.
I was able to configure nginx to handle normal requests and even the redirects coming form splunkweb in the right way but it seems some of the assets contained in the page are not referenced relative to the current page but rather contain an absolute path which is determined based on the Host-field in the request issued from the proxy.
Is there some way to let splunk know that it is supposed to run from some other endpoint than /? So that it can inject this endpoint into all links (by prefixing them) that are needed for the dynamic parts of the page.
Thanks in advance!

0 Karma
1 Solution

sh4kesbeer
Explorer

Okay there is a root_endpoint option for the web.conf which works as expected. It seems I did oversee this initially

View solution in original post

sh4kesbeer
Explorer

Okay there is a root_endpoint option for the web.conf which works as expected. It seems I did oversee this initially

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Automated Threat Analysis: Available in ES Premier

Automated Threat Analysis: Centralize and Accelerate Phishing Investigations in Splunk Enterprise ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...