Splunk Enterprise Security

Splunk ES: Failed to update finding: cannot redirect an already redirected call

MU2DOD
Loves-to-Learn

Greetings.

We are currently using Splunk ES (on-prem) 7.3.3, I updated Splunk to version 9.4.1. Since the upgrade we're unable to edit ES findings. For instance If i try to edit a a finding so it can be reassigned to someone, or closed. I receive the following error pop-up: 

"Failure
Failed to update finding: Cannot redirect an already redirected call"

 

I haven't been able to locate any resources that maybe able to help point in the right directions. Any help would be appreciated. 

0 Karma

MU2DOD
Loves-to-Learn

<removed>

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @MU2DOD 

It looks like you're experiencing an issue which first started in ES8. Check out https://splunk.my.site.com/customer/s/article/Mission-control-8-0-fails-to-assign for more detailed info, however I believe the following should fix the issue for you:

  • ensure that FQDN instead of ServerName is set in server.conf in the whole environment
    • do that step if splunkd logs, reference hostnames (names without domain names, meaning non-FQDN) over HTTPS
    • set sslVerifyServerCert and sslVerifyServerName to true in all instances
    • then restart the whole Splunk Environment where changes have been made
    • push the bundle from the deployer to the SHC members
  • Once that is done, then in Mission Control, manually add Investigation Types (which previously wasn't working)
    • then set the newly added type as the default
    • then editing notable events, adding custom fields, and other should work

Please let me know how you get on and consider adding karma to this or any other answer if it has helped.
Regards

Will

0 Karma

MU2DOD
Loves-to-Learn

Hi @livehybrid 

For "set sslVerifyServerCert and sslVerifyServerName," there are 5 stanzas in server.conf that has these keys available. Do I need set these to true for all 5?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...