Until I install the ES on the enterprise platform I could connect via 127.0.0.1:8000 via secure https connection. However after the ES installation, https stops connecting and I have to connect through non-secure connection.
Changing EnableWebSSL parameter to Yes or No does not have any impact.
How can I connect secure to my NFR Enterprise environment?
Thanks.
Ugur
Thanks for the feedback.
How can I check this?
3.web.conf should n't override in the ES App.
Check web.conf settings
Make sure the following key is present and correct
[settings]
enableWebSSL = true
privKeyPath = $SPLUNK_HOME/etc/auth/mycerts/your_private.key
serverCert = $SPLUNK_HOME/etc/auth/mycerts/your_certificate.pem
If you're not using custom certificates, Splunk will default to:
privKeyPath = $SPLUNK_HOME/etc/auth/splunkweb/privkey.pem
serverCert = $SPLUNK_HOME/etc/auth/splunkweb/cert.pem
And confirm that ES is not over writing web.conf
you can use the below command to find the directory
find $SPLUNK_HOME/etc/apps/SplunkEnterpriseSecuritySuite -name web.conf
modify the command based on your app setup, if you found any config check the stanza like below
[settings]
enableWebSSL = false
use the below btool command and validate the stanza
$SPLUNK_HOME/bin/splunk btool web list --debug
Once you modified restart the Splunk services.
Quick overview:
1.enableWebSSL= true in the /system/local/web.conf
2.Privkeypath and Servercert should be exist and readable
3.web.conf should n't override in the ES App.
Refer this