Splunk Enterprise Security

Splunk Enterprise Security: Phantom IP address "refused to connect" on Google Chrome


Hello, I'm trying to access the Phantom web servers but when I use the IP address into Chrome, it says it "refused to connect".
I am also running the .ova file in VMware Player 15 and the network adapter is set to NAT.
Is there any way around this so I can access Phantom?

Note: I am attempting to access it from my work computer which has limited internet access, but I hope that doesn't affect too much.

0 Karma

Splunk Employee
Splunk Employee

Are you able to post a screenshot? The out-of-the-box SSL Cert for Phantom webUI is not valid (self signed) so hopefully this is as simple as that and you just need to click the link to proceed.

0 Karma

Splunk Employee
Splunk Employee

Are you running it locally on your work computer? Are you using port forwarding ?
Normally it would be these ports:
TCP 22 Used for administering the operating system.
TCP 80 Port for requests sent over HTTP. Splunk Phantom redirects all HTTP requests to HTTPS.
TCP 443 HTTPS port for the web interface and REST API. This port must be exposed to access Splunk Phantom services.
so https://ip-address:443 for web interface

But if you're running it locally & using port forwarding it could be:
(replace with whatever IP/port you've chosen for your host IP and host port)

Splunk Employee
Splunk Employee

In addition, I'd suggest making sure that you can ping the IP address from the CLI, it's entirely likely that something on your work computer could be preventing the connection. If you can ping the IP address, that means it's at least reachable on your network from your computer.

Get Updates on the Splunk Community!

2024 Splunk Career Impact Survey | Earn a $20 gift card for participating!

Hear ye, hear ye! The time has come again for Splunk's annual Career Impact Survey!  We need your help by ...

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...