Splunk Enterprise Security

Is this IP safe //127.0.0.1:8000/en-US/account/login?return_to=%2Fen-US%2F

jcodjo3
Explorer

I tried to log into slunk enterprise and was told by 2 web browsers chrome and edge that the security certificate had expired for the website and that it could be under potential attack.  Is this a generic browser message or should this be considered a security risk.

0 Karma

renjith_nair
Legend

127.0.0.1 is the loopback IP address aka the localhost. So you installed splunk on the same machine from where you are trying to access. Now you know whether its safe or not 🙂

 

---
What goes around comes around. If it helps, hit it with Karma 🙂
0 Karma

isoutamo
SplunkTrust
SplunkTrust

In this particular case if all connection has done via 127.0.0.1 this is not an issue. But/when there are connections with it's public address then you should fix it by renewing the server's certificate. If you are using Splunk's own (not recommended) then it's usually renewer when you are updating splunk. And when you are using your own/official you must do it by yourself.

r. Ismo

0 Karma
Get Updates on the Splunk Community!

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...