Splunk Enterprise Security

Splunk ES: Failed to update finding: cannot redirect an already redirected call

MU2DOD
Loves-to-Learn

Greetings.

We are currently using Splunk ES (on-prem) 7.3.3, I updated Splunk to version 9.4.1. Since the upgrade we're unable to edit ES findings. For instance If i try to edit a a finding so it can be reassigned to someone, or closed. I receive the following error pop-up: 

"Failure
Failed to update finding: Cannot redirect an already redirected call"

 

I haven't been able to locate any resources that maybe able to help point in the right directions. Any help would be appreciated. 

0 Karma

MU2DOD
Loves-to-Learn

<removed>

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @MU2DOD 

It looks like you're experiencing an issue which first started in ES8. Check out https://splunk.my.site.com/customer/s/article/Mission-control-8-0-fails-to-assign for more detailed info, however I believe the following should fix the issue for you:

  • ensure that FQDN instead of ServerName is set in server.conf in the whole environment
    • do that step if splunkd logs, reference hostnames (names without domain names, meaning non-FQDN) over HTTPS
    • set sslVerifyServerCert and sslVerifyServerName to true in all instances
    • then restart the whole Splunk Environment where changes have been made
    • push the bundle from the deployer to the SHC members
  • Once that is done, then in Mission Control, manually add Investigation Types (which previously wasn't working)
    • then set the newly added type as the default
    • then editing notable events, adding custom fields, and other should work

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma

MU2DOD
Loves-to-Learn

Hi @livehybrid 

For "set sslVerifyServerCert and sslVerifyServerName," there are 5 stanzas in server.conf that has these keys available. Do I need set these to true for all 5?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...