Splunk Enterprise

After installation of ES over the NFR Splunk Enteprise platform, https secure connection to the platform does not work

unluakin
Loves-to-Learn Lots

Until I install the ES on the enterprise platform I could connect via 127.0.0.1:8000 via secure https connection. However after the ES installation, https stops connecting and I have to connect through non-secure connection.

Changing EnableWebSSL parameter to Yes or No does not have any impact.

How can I connect secure to my NFR Enterprise environment?

Thanks.

Ugur

Labels (2)
0 Karma

unluakin
Loves-to-Learn Lots

Thanks for the feedback.

 

How can I check this?

 

3.web.conf should n't override in the ES App.

 

 

0 Karma

thahir
Contributor

Hi @unluakin 

 

use the below btool command and check

 

$SPLUNK_HOME/bin/splunk btool web list --debug

0 Karma

thahir
Contributor

Check web.conf settings

Make sure the following key is present and correct

[settings]
enableWebSSL = true
privKeyPath = $SPLUNK_HOME/etc/auth/mycerts/your_private.key
serverCert = $SPLUNK_HOME/etc/auth/mycerts/your_certificate.pem

 

If you're not using custom certificates, Splunk will default to:

 

privKeyPath = $SPLUNK_HOME/etc/auth/splunkweb/privkey.pem
serverCert = $SPLUNK_HOME/etc/auth/splunkweb/cert.pem

 

And confirm that ES is not over writing web.conf

you can use the below command to find the directory

 

find $SPLUNK_HOME/etc/apps/SplunkEnterpriseSecuritySuite -name web.conf

 

modify the command based on your app setup, if you found any config check the stanza like below

 

[settings]
enableWebSSL = false

 

use the below btool command and validate the stanza

$SPLUNK_HOME/bin/splunk btool web list --debug

Once you modified restart the Splunk services.

 Quick overview:

1.enableWebSSL= true in the /system/local/web.conf

2.Privkeypath and Servercert should be exist and readable

3.web.conf should n't override in the ES App.

0 Karma

kiran_panchavat
SplunkTrust
SplunkTrust

@unluakin 

Refer this

ERROR: IP address 127.0.0.1 not in server certificate. Please see server.conf/[sslConfig]/cliVerifyS...

Configure TLS certificate host name validation for secured connections between Splunk software compo...

Did this help? If yes, please consider giving kudos, marking it as the solution, or commenting for clarification — your feedback keeps the community going!
0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...