Splunk Enterprise Security

Setting up Demisto in Splunk?

cltqchevron
New Member

I'm hosting both Demisto and Splunk ES (Both free edition) on the same network. I have added the API key for Splunk in Demisto and tested successfully. However, when i tried to setup Demisto in Splunk, I keyed in the API key and Demisto IP Address and received an error:
"Encountered the following error while trying to update: Error while posting to url=/servicesNS/nobody/TA-Demisto/demisto/demistocustomendpoint/demistoenv"

I have no certificate and am not using a proxy so the rest of the fields are empty.
Anyone encountered the same issue and can help me out with this? Many thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...