Splunk Enterprise Security

Splunk ES: Failed to update finding: cannot redirect an already redirected call

MU2DOD
Loves-to-Learn

Greetings.

We are currently using Splunk ES (on-prem) 7.3.3, I updated Splunk to version 9.4.1. Since the upgrade we're unable to edit ES findings. For instance If i try to edit a a finding so it can be reassigned to someone, or closed. I receive the following error pop-up: 

"Failure
Failed to update finding: Cannot redirect an already redirected call"

 

I haven't been able to locate any resources that maybe able to help point in the right directions. Any help would be appreciated. 

0 Karma

MU2DOD
Loves-to-Learn

<removed>

0 Karma

livehybrid
Champion

Hi @MU2DOD 

It looks like you're experiencing an issue which first started in ES8. Check out https://splunk.my.site.com/customer/s/article/Mission-control-8-0-fails-to-assign for more detailed info, however I believe the following should fix the issue for you:

  • ensure that FQDN instead of ServerName is set in server.conf in the whole environment
    • do that step if splunkd logs, reference hostnames (names without domain names, meaning non-FQDN) over HTTPS
    • set sslVerifyServerCert and sslVerifyServerName to true in all instances
    • then restart the whole Splunk Environment where changes have been made
    • push the bundle from the deployer to the SHC members
  • Once that is done, then in Mission Control, manually add Investigation Types (which previously wasn't working)
    • then set the newly added type as the default
    • then editing notable events, adding custom fields, and other should work

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma

MU2DOD
Loves-to-Learn

Hi @livehybrid 

For "set sslVerifyServerCert and sslVerifyServerName," there are 5 stanzas in server.conf that has these keys available. Do I need set these to true for all 5?

0 Karma
Get Updates on the Splunk Community!

Detecting Brute Force Account Takeover Fraud with Splunk

This article is the second in a three-part series exploring advanced fraud detection techniques using Splunk. ...

Buttercup Games: Further Dashboarding Techniques (Part 9)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Buttercup Games: Further Dashboarding Techniques (Part 8)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...