Security

Require.js with reverse proxy

wazuhtest
Explorer

Hi team. I'm facing problems with my splunk app due to require.js, let me explain myself:
My app structure is like this:
.
├── CHANGELOG.md
├── LICENSE
├── README.md
└── SplunkAppForWazuh
├── appserver
│   ├── controllers
│   │   ├── agents.py
│   │   ├── cluster.py
│   │   └── manager.py
│   └── static
│   ├── css
│   │   ├── images
│   │   │   ├── sort_asc_disabled.png
│   │   │   ├── sort_asc.png
│   │   │   ├── sort_both.png
│   │   │   ├── sort_desc_disabled.png
│   │   │   └── sort_desc.png
│   │   ├── styles
│   │   │   ├── table_decorations.css
│   │   │   ├── toast.css
│   │   │   └── wazuh_decorations.css
│   │   └── thirdPartyStyles
│   │   └── font-awesome
│   │   ├── css
│   │   │   ├── font-awesome.css
│   │   │   └── font-awesome.min.css
│   │   └── fonts
│   │   ├── FontAwesome.otf
│   │   ├── fontawesome-webfont.eot
│   │   ├── fontawesome-webfont.svg
│   │   ├── fontawesome-webfont.ttf
│   │   ├── fontawesome-webfont.woff
│   │   └── fontawesome-webfont.woff2
│   ├── js
│   │   ├── directives
│   │   │   ├── agentsTable.js
│   │   │   ├── selectedCredentialsDirective.js
│   │   │   ├── tableView.js
│   │   │   └── toaster.js
│   │   ├── services
│   │   │   ├── apiService.js
│   │   │   ├── credentialService.js
│   │   │   ├── indexService.js
│   │   │   ├── localStorage.js
│   │   │   └── promisedReq.js
│   │   └── viewControllers
│   │   ├── agentsConfiguration.js
│   │   ├── agent_summary.js
│   │   ├── audit.js
│   │   ├── cis.js
│   │   ├── configuration.js
│   │   ├── fim.js
│   │   ├── gdpr.js
│   │   ├── general.js
│   │   ├── groups.js
│   │   ├── logs.js
│   │   ├── manager_decoders.js
│   │   ├── manager_ruleset.js
│   │   ├── manager_status.js
│   │   ├── openscap.js
│   │   ├── overview_audit.js
│   │   ├── overview_fim.js
│   │   ├── overview_gdpr.js
│   │   ├── overview_pci_dss.js
│   │   ├── overview_policy_monitoring.js
│   │   ├── overview_scap.js
│   │   ├── pcidss.js
│   │   ├── selectIndex.js
│   │   ├── settings.js
│   │   └── wazuh_alerts.js
│   └── views
│   ├── agentConfigurationViews
│   │   ├── ciscat.html
│   │   ├── fileIntegrity.html
│   │   ├── logCollection.html
│   │   ├── openSCAP.html
│   │   ├── policyMonitoring.html
│   │   ├── remoteCommand.html
│   │   └── syscollector.html
│   └── managerConfigurationViews
│   ├── auth.html
│   ├── cluster.html
│   ├── command.html
│   ├── global.html
│   ├── remote.html
│   ├── rootcheck.html
│   ├── ruleset.html
│   └── syscheck.html
├── bin
│   ├── get_agents_check.py
│   ├── get_agents_from_group.py
│   ├── get_agents_info.py
│   ├── get_agents.py
│   ├── get_agents_status.py
│   ├── get_agents_summary.py
│   ├── get_current_version.py
│   ├── get_decoders.py
│   ├── get_file_content.py
│   ├── get_files_from_group.py
│   ├── get_groups.py
│   ├── get_manager_logs.py
│   ├── get_manager_status.py
│   ├── get_ruleset.py
│   ├── README
│   └── splunklib
│   ├── binding.py
│   ├── client.py
│   ├── data.py
│   ├── init.py
│   ├── ordereddict.py
│   ├── results.py
│   └── six.py
├── default
│   ├── app.conf
│   ├── collections.conf
│   ├── commands.conf
│   ├── config.conf
│   ├── data
│   │   └── ui
│   │   ├── html
│   │   │   ├── ab_general.html
│   │   │   ├── agents_configuration.html
│   │   │   ├── agents_summary.html
│   │   │   ├── audit.html
│   │   │   ├── cis.html
│   │   │   ├── configuration.html
│   │   │   ├── fim.html
│   │   │   ├── gdpr.html
│   │   │   ├── groups.html
│   │   │   ├── logs.html
│   │   │   ├── manager_decoders.html
│   │   │   ├── manager_ruleset.html
│   │   │   ├── manager_status.html
│   │   │   ├── openscap.html
│   │   │   ├── overview_audit.html
│   │   │   ├── overview_fim.html
│   │   │   ├── overview_gdpr.html
│   │   │   ├── overview_pci_dss.html
│   │   │   ├── overview_policy_monitoring.html
│   │   │   ├── overview_scap.html
│   │   │   ├── pcidss.html
│   │   │   ├── select_index.html
│   │   │   ├── settings.html
│   │   │   └── wazuh_alerts.html
│   │   ├── nav
│   │   │   └── default.xml
│   │   └── views
│   │   └── README
│   ├── indexes.conf
│   ├── inputs.conf
│   ├── package.conf
│   ├── props.conf
│   ├── transforms.conf
│   └── web.conf
├── lookups
│   ├── gdpr.csv
│   └── pci1.csv
├── metadata
│   ├── default.meta
│   └── local.meta
└── static
├── appIcon_2x.png
├── appIconAlt_2x.png
├── appIconAlt.png
├── appIcon.png
├── appLogo_2x.png
├── appLogo.png
└── screenshot.png

And the way I'm using for importing modules with require is the following, for example in settings.js:

require([
"splunkjs/mvc",
"splunkjs/mvc/utils",
"splunkjs/mvc/simplexml",
"splunkjs/mvc/simplexml/dashboardview",
"underscore",
"splunkjs/mvc/tokenutils",
"jquery",
"splunkjs/mvc/layoutview",
"splunkjs/mvc/simplexml/dashboardview",
"/static/app/SplunkAppForWazuh/js/services/credentialService.js",
"/static/app/SplunkAppForWazuh/js/services/apiService.js",
"/static/app/SplunkAppForWazuh/js/services/indexService.js",
"/static/app/SplunkAppForWazuh/js/directives/toaster",
"splunkjs/mvc/simplexml/searcheventhandler",
"splunkjs/mvc/simpleform/input/dropdown",
"splunkjs/mvc/searchmanager",
"splunkjs/mvc/simplexml/urltokenmodel",
"splunkjs/mvc/simpleform/formutils"

],
function (
mvc,
utils,
DashboardController,
Dashboard,
_,
TokenUtils,
$,
LayoutView,
Dashboard,
CredentialService,
ApiService,
IndexService,
Toast,
SearchEventHandler,
DropdownInput,
SearchManager,
UrlTokenModel,
FormUtils
) { ...

As you can see, I'm importing my own modules by hardcoding the URL like this:
...
"/static/app/SplunkAppForWazuh/js/services/indexService.js",
...

And works great, I access my app in this url: http://IP:8000/en-US/app/SplunkAppForWazuh/settings and al dependencies works fine,
but when accessing via a reverse proxy, I get 404s in the reverse proxy that it cannot find the js files.

´´´

tail -F /var/log/nginx/*.log | grep -i wazuh

client_user_ip - - [13/Jun/2018:08:16:31 -0400] "GET /splunk/en-GB/splunkd/raw/servicesNS/my_splunk_user_name/SplunkAppForWazuh/static/appIconAlt.png HTTP/1.1" 200 2082 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:33 -0400] "GET /splunk/en-GB/app/SplunkAppForWazuh HTTP/1.1" 303 129 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:33 -0400] "GET /splunk/en-GB/app/SplunkAppForWazuh/API HTTP/1.1" 200 1410 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:33 -0400] "GET /splunk//en-GB/static/@6EE0DA5BC97D7879008A1F199F82807231E52F81507E4FF3E4B5145031DDA25C/build/css/bootstrap-enterprise.css HTTP/1.1" 200 24686 "https://proxy_ip_address/splunk/en-GB/app/SplunkAppForWazuh/API" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:33 -0400] "GET /splunk//en-GB/static/@6EE0DA5BC97D7879008A1F199F82807231E52F81507E4FF3E4B5145031DDA25C/css/build/pages/dashboard-simple-bootstrap.min.css HTTP/1.1" 200 169 "https://proxy_ip_address/splunk/en-GB/app/SplunkAppForWazuh/API" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:33 -0400] "GET /splunk//en-GB/static/@6EE0DA5BC97D7879008A1F199F82807231E52F81507E4FF3E4B5145031DDA25C/app/SplunkAppForWazuh/css/styles/toast.css HTTP/1.1" 200 3264 "https://proxy_ip_address/splunk/en-GB/app/SplunkAppForWazuh/API" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:33 -0400] "GET /splunk//en-GB/static/@6EE0DA5BC97D7879008A1F199F82807231E52F81507E4FF3E4B5145031DDA25C/app/SplunkAppForWazuh/css/styles/wazuh_decorations.css HTTP/1.1" 200 1031 "https://proxy_ip_address/splunk/en-GB/app/SplunkAppForWazuh/API" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:33 -0400] "GET /splunk//en-GB/static/@6EE0DA5BC97D7879008A1F199F82807231E52F81507E4FF3E4B5145031DDA25C/app/SplunkAppForWazuh/js/viewControllers/APIconf.js HTTP/1.1" 200 3298 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:34 -0400] "GET /splunk//en-GB/splunkd/
raw/services/apps/local/SplunkAppForWazuh?output_mode=json&=1528892194220 HTTP/1.1" 200 773 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:34 -0400] "GET /splunk//en-GB/splunkd/
raw/servicesNS/my_splunk_user_name/SplunkAppForWazuh/data/ui/times?output_mode=json&count=-1&=1528892194224 HTTP/1.1" 200 1959 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:34 -0400] "GET /splunk/en-GB/splunkd/raw/servicesNS/my_splunk_user_name/SplunkAppForWazuh/data/ui/views/API?output_mode=json&_=1528892194226 HTTP/1.1" 200 1886 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:34 -0400] "GET /splunk//en-GB/splunkd/
raw/servicesNS/my_splunk_user_name/SplunkAppForWazuh/configs/conf-visualizations?output_mode=json&search=disabled%3D0&count=0&_=1528892194229 HTTP/1.1" 200 275 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:34 -0400] "GET /splunk/en-GB/app/SplunkAppForWazuh/js/customViews/toaster.js HTTP/1.1" 404 1401 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:34 -0400] "GET /splunk/en-GB/app/SplunkAppForWazuh/js/utilLib/promisedReq.js HTTP/1.1" 404 1401 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:34 -0400] "GET /splunk/en-GB/app/SplunkAppForWazuh/js/utilLib/services.js HTTP/1.1" 404 1401 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
```

Notice that "GET /splunk/en-GB/app/SplunkAppForWazuh/js/utilLib/services.js HTTP/1.1" - 404

Any ideas? Thank you so much!

Labels (1)
0 Karma

lucacaldiero
Path Finder

Hi, I am facing the same problem.
Please, have you found a solution?

Thanks in advance.

0 Karma
Get Updates on the Splunk Community!

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...