Security

Require.js with reverse proxy

wazuhtest
Explorer

Hi team. I'm facing problems with my splunk app due to require.js, let me explain myself:
My app structure is like this:
.
├── CHANGELOG.md
├── LICENSE
├── README.md
└── SplunkAppForWazuh
├── appserver
│   ├── controllers
│   │   ├── agents.py
│   │   ├── cluster.py
│   │   └── manager.py
│   └── static
│   ├── css
│   │   ├── images
│   │   │   ├── sort_asc_disabled.png
│   │   │   ├── sort_asc.png
│   │   │   ├── sort_both.png
│   │   │   ├── sort_desc_disabled.png
│   │   │   └── sort_desc.png
│   │   ├── styles
│   │   │   ├── table_decorations.css
│   │   │   ├── toast.css
│   │   │   └── wazuh_decorations.css
│   │   └── thirdPartyStyles
│   │   └── font-awesome
│   │   ├── css
│   │   │   ├── font-awesome.css
│   │   │   └── font-awesome.min.css
│   │   └── fonts
│   │   ├── FontAwesome.otf
│   │   ├── fontawesome-webfont.eot
│   │   ├── fontawesome-webfont.svg
│   │   ├── fontawesome-webfont.ttf
│   │   ├── fontawesome-webfont.woff
│   │   └── fontawesome-webfont.woff2
│   ├── js
│   │   ├── directives
│   │   │   ├── agentsTable.js
│   │   │   ├── selectedCredentialsDirective.js
│   │   │   ├── tableView.js
│   │   │   └── toaster.js
│   │   ├── services
│   │   │   ├── apiService.js
│   │   │   ├── credentialService.js
│   │   │   ├── indexService.js
│   │   │   ├── localStorage.js
│   │   │   └── promisedReq.js
│   │   └── viewControllers
│   │   ├── agentsConfiguration.js
│   │   ├── agent_summary.js
│   │   ├── audit.js
│   │   ├── cis.js
│   │   ├── configuration.js
│   │   ├── fim.js
│   │   ├── gdpr.js
│   │   ├── general.js
│   │   ├── groups.js
│   │   ├── logs.js
│   │   ├── manager_decoders.js
│   │   ├── manager_ruleset.js
│   │   ├── manager_status.js
│   │   ├── openscap.js
│   │   ├── overview_audit.js
│   │   ├── overview_fim.js
│   │   ├── overview_gdpr.js
│   │   ├── overview_pci_dss.js
│   │   ├── overview_policy_monitoring.js
│   │   ├── overview_scap.js
│   │   ├── pcidss.js
│   │   ├── selectIndex.js
│   │   ├── settings.js
│   │   └── wazuh_alerts.js
│   └── views
│   ├── agentConfigurationViews
│   │   ├── ciscat.html
│   │   ├── fileIntegrity.html
│   │   ├── logCollection.html
│   │   ├── openSCAP.html
│   │   ├── policyMonitoring.html
│   │   ├── remoteCommand.html
│   │   └── syscollector.html
│   └── managerConfigurationViews
│   ├── auth.html
│   ├── cluster.html
│   ├── command.html
│   ├── global.html
│   ├── remote.html
│   ├── rootcheck.html
│   ├── ruleset.html
│   └── syscheck.html
├── bin
│   ├── get_agents_check.py
│   ├── get_agents_from_group.py
│   ├── get_agents_info.py
│   ├── get_agents.py
│   ├── get_agents_status.py
│   ├── get_agents_summary.py
│   ├── get_current_version.py
│   ├── get_decoders.py
│   ├── get_file_content.py
│   ├── get_files_from_group.py
│   ├── get_groups.py
│   ├── get_manager_logs.py
│   ├── get_manager_status.py
│   ├── get_ruleset.py
│   ├── README
│   └── splunklib
│   ├── binding.py
│   ├── client.py
│   ├── data.py
│   ├── init.py
│   ├── ordereddict.py
│   ├── results.py
│   └── six.py
├── default
│   ├── app.conf
│   ├── collections.conf
│   ├── commands.conf
│   ├── config.conf
│   ├── data
│   │   └── ui
│   │   ├── html
│   │   │   ├── ab_general.html
│   │   │   ├── agents_configuration.html
│   │   │   ├── agents_summary.html
│   │   │   ├── audit.html
│   │   │   ├── cis.html
│   │   │   ├── configuration.html
│   │   │   ├── fim.html
│   │   │   ├── gdpr.html
│   │   │   ├── groups.html
│   │   │   ├── logs.html
│   │   │   ├── manager_decoders.html
│   │   │   ├── manager_ruleset.html
│   │   │   ├── manager_status.html
│   │   │   ├── openscap.html
│   │   │   ├── overview_audit.html
│   │   │   ├── overview_fim.html
│   │   │   ├── overview_gdpr.html
│   │   │   ├── overview_pci_dss.html
│   │   │   ├── overview_policy_monitoring.html
│   │   │   ├── overview_scap.html
│   │   │   ├── pcidss.html
│   │   │   ├── select_index.html
│   │   │   ├── settings.html
│   │   │   └── wazuh_alerts.html
│   │   ├── nav
│   │   │   └── default.xml
│   │   └── views
│   │   └── README
│   ├── indexes.conf
│   ├── inputs.conf
│   ├── package.conf
│   ├── props.conf
│   ├── transforms.conf
│   └── web.conf
├── lookups
│   ├── gdpr.csv
│   └── pci1.csv
├── metadata
│   ├── default.meta
│   └── local.meta
└── static
├── appIcon_2x.png
├── appIconAlt_2x.png
├── appIconAlt.png
├── appIcon.png
├── appLogo_2x.png
├── appLogo.png
└── screenshot.png

And the way I'm using for importing modules with require is the following, for example in settings.js:

require([
"splunkjs/mvc",
"splunkjs/mvc/utils",
"splunkjs/mvc/simplexml",
"splunkjs/mvc/simplexml/dashboardview",
"underscore",
"splunkjs/mvc/tokenutils",
"jquery",
"splunkjs/mvc/layoutview",
"splunkjs/mvc/simplexml/dashboardview",
"/static/app/SplunkAppForWazuh/js/services/credentialService.js",
"/static/app/SplunkAppForWazuh/js/services/apiService.js",
"/static/app/SplunkAppForWazuh/js/services/indexService.js",
"/static/app/SplunkAppForWazuh/js/directives/toaster",
"splunkjs/mvc/simplexml/searcheventhandler",
"splunkjs/mvc/simpleform/input/dropdown",
"splunkjs/mvc/searchmanager",
"splunkjs/mvc/simplexml/urltokenmodel",
"splunkjs/mvc/simpleform/formutils"

],
function (
mvc,
utils,
DashboardController,
Dashboard,
_,
TokenUtils,
$,
LayoutView,
Dashboard,
CredentialService,
ApiService,
IndexService,
Toast,
SearchEventHandler,
DropdownInput,
SearchManager,
UrlTokenModel,
FormUtils
) { ...

As you can see, I'm importing my own modules by hardcoding the URL like this:
...
"/static/app/SplunkAppForWazuh/js/services/indexService.js",
...

And works great, I access my app in this url: http://IP:8000/en-US/app/SplunkAppForWazuh/settings and al dependencies works fine,
but when accessing via a reverse proxy, I get 404s in the reverse proxy that it cannot find the js files.

´´´

tail -F /var/log/nginx/*.log | grep -i wazuh

client_user_ip - - [13/Jun/2018:08:16:31 -0400] "GET /splunk/en-GB/splunkd/raw/servicesNS/my_splunk_user_name/SplunkAppForWazuh/static/appIconAlt.png HTTP/1.1" 200 2082 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:33 -0400] "GET /splunk/en-GB/app/SplunkAppForWazuh HTTP/1.1" 303 129 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:33 -0400] "GET /splunk/en-GB/app/SplunkAppForWazuh/API HTTP/1.1" 200 1410 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:33 -0400] "GET /splunk//en-GB/static/@6EE0DA5BC97D7879008A1F199F82807231E52F81507E4FF3E4B5145031DDA25C/build/css/bootstrap-enterprise.css HTTP/1.1" 200 24686 "https://proxy_ip_address/splunk/en-GB/app/SplunkAppForWazuh/API" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:33 -0400] "GET /splunk//en-GB/static/@6EE0DA5BC97D7879008A1F199F82807231E52F81507E4FF3E4B5145031DDA25C/css/build/pages/dashboard-simple-bootstrap.min.css HTTP/1.1" 200 169 "https://proxy_ip_address/splunk/en-GB/app/SplunkAppForWazuh/API" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:33 -0400] "GET /splunk//en-GB/static/@6EE0DA5BC97D7879008A1F199F82807231E52F81507E4FF3E4B5145031DDA25C/app/SplunkAppForWazuh/css/styles/toast.css HTTP/1.1" 200 3264 "https://proxy_ip_address/splunk/en-GB/app/SplunkAppForWazuh/API" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:33 -0400] "GET /splunk//en-GB/static/@6EE0DA5BC97D7879008A1F199F82807231E52F81507E4FF3E4B5145031DDA25C/app/SplunkAppForWazuh/css/styles/wazuh_decorations.css HTTP/1.1" 200 1031 "https://proxy_ip_address/splunk/en-GB/app/SplunkAppForWazuh/API" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:33 -0400] "GET /splunk//en-GB/static/@6EE0DA5BC97D7879008A1F199F82807231E52F81507E4FF3E4B5145031DDA25C/app/SplunkAppForWazuh/js/viewControllers/APIconf.js HTTP/1.1" 200 3298 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:34 -0400] "GET /splunk//en-GB/splunkd/
raw/services/apps/local/SplunkAppForWazuh?output_mode=json&=1528892194220 HTTP/1.1" 200 773 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:34 -0400] "GET /splunk//en-GB/splunkd/
raw/servicesNS/my_splunk_user_name/SplunkAppForWazuh/data/ui/times?output_mode=json&count=-1&=1528892194224 HTTP/1.1" 200 1959 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:34 -0400] "GET /splunk/en-GB/splunkd/raw/servicesNS/my_splunk_user_name/SplunkAppForWazuh/data/ui/views/API?output_mode=json&_=1528892194226 HTTP/1.1" 200 1886 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:34 -0400] "GET /splunk//en-GB/splunkd/
raw/servicesNS/my_splunk_user_name/SplunkAppForWazuh/configs/conf-visualizations?output_mode=json&search=disabled%3D0&count=0&_=1528892194229 HTTP/1.1" 200 275 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:34 -0400] "GET /splunk/en-GB/app/SplunkAppForWazuh/js/customViews/toaster.js HTTP/1.1" 404 1401 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:34 -0400] "GET /splunk/en-GB/app/SplunkAppForWazuh/js/utilLib/promisedReq.js HTTP/1.1" 404 1401 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
client_user_ip - - [13/Jun/2018:08:16:34 -0400] "GET /splunk/en-GB/app/SplunkAppForWazuh/js/utilLib/services.js HTTP/1.1" 404 1401 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/66.0.3359.181 Chrome/66.0.3359.181 Safari/537.36"
```

Notice that "GET /splunk/en-GB/app/SplunkAppForWazuh/js/utilLib/services.js HTTP/1.1" - 404

Any ideas? Thank you so much!

Labels (1)
0 Karma

lucacaldiero
Path Finder

Hi, I am facing the same problem.
Please, have you found a solution?

Thanks in advance.

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...