Splunk Enterprise

After installation of ES over the NFR Splunk Enteprise platform, https secure connection to the platform does not work

unluakin
Loves-to-Learn Lots

Until I install the ES on the enterprise platform I could connect via 127.0.0.1:8000 via secure https connection. However after the ES installation, https stops connecting and I have to connect through non-secure connection.

Changing EnableWebSSL parameter to Yes or No does not have any impact.

How can I connect secure to my NFR Enterprise environment?

Thanks.

Ugur

Labels (2)
0 Karma

unluakin
Loves-to-Learn Lots

Thanks for the feedback.

 

How can I check this?

 

3.web.conf should n't override in the ES App.

 

 

0 Karma

thahir
Path Finder

Hi @unluakin 

 

use the below btool command and check

 

$SPLUNK_HOME/bin/splunk btool web list --debug

0 Karma

thahir
Path Finder

Check web.conf settings

Make sure the following key is present and correct

[settings]
enableWebSSL = true
privKeyPath = $SPLUNK_HOME/etc/auth/mycerts/your_private.key
serverCert = $SPLUNK_HOME/etc/auth/mycerts/your_certificate.pem

 

If you're not using custom certificates, Splunk will default to:

 

privKeyPath = $SPLUNK_HOME/etc/auth/splunkweb/privkey.pem
serverCert = $SPLUNK_HOME/etc/auth/splunkweb/cert.pem

 

And confirm that ES is not over writing web.conf

you can use the below command to find the directory

 

find $SPLUNK_HOME/etc/apps/SplunkEnterpriseSecuritySuite -name web.conf

 

modify the command based on your app setup, if you found any config check the stanza like below

 

[settings]
enableWebSSL = false

 

use the below btool command and validate the stanza

$SPLUNK_HOME/bin/splunk btool web list --debug

Once you modified restart the Splunk services.

 Quick overview:

1.enableWebSSL= true in the /system/local/web.conf

2.Privkeypath and Servercert should be exist and readable

3.web.conf should n't override in the ES App.

0 Karma

kiran_panchavat
Influencer

@unluakin 

Refer this

ERROR: IP address 127.0.0.1 not in server certificate. Please see server.conf/[sslConfig]/cliVerifyS...

Configure TLS certificate host name validation for secured connections between Splunk software compo...

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Get Updates on the Splunk Community!

Why You Can't Miss .conf25: Unleashing the Power of Agentic AI with Splunk & Cisco

The Defining Technology Movement of Our Lifetime The advent of agentic AI is arguably the defining technology ...

Deep Dive into Federated Analytics: Unlocking the Full Power of Your Security Data

In today’s complex digital landscape, security teams face increasing pressure to protect sprawling data across ...

Your summer travels continue with new course releases

Summer in the Northern hemisphere is in full swing, and is often a time to travel and explore. If your summer ...