Splunk SOAR

Can't connect Splunk SOAR to Splunk Enterprise Security

Alan_Chan
Explorer

I am using Enterprise 9.3.2, ES 8.1.0, and SOAR 6.4.1 to test the pairing function. Both devices are on-premises and in the same subnet, with no network issues between them. However, when I try to use the pairing function in ES, the following error message appears:
"Cannot connect to SOAR. Check that the ES IP address is included on the SOAR stack allow list."

When I check the internal log, it shows the following error:
"Unexpected error when attempting pairing: HTTPSConnectionPool(host='xxx.xxx.xxx.xxx', port=8443): Max retries exceeded with URL: /rest/version (Caused by SSLError(SSLError(1, '[SSL: SSLV3_ALERT_HANDSHAKE_FAILURE] sslv3 alert handshake failure (_ssl.c:1143)')))".

Does anyone have any ideas on how to resolve this?

Labels (1)
0 Karma

PrewinThomas
Motivator

@Alan_Chan 

Is your ES IP added to your SOAR allow list?
Check connection before pairing - Confirm that Enterprise Security can initiate a TCP connection for REST calls to the SOAR port
Also error highlights SSL handshake failure-Are you using self signed or valid CA certificate in the SOAR?
Also note that, Splunk Enterprise Security requires a valid SSL certificate to communicate with Splunk SOAR

Ref:#https://help.splunk.com/en/splunk-enterprise-security-8/administer/8.0/configuration-and-settings/pa...

 

Regards,
Prewin
Splunk Enthusiast | Always happy to help! If this answer helped you, please consider marking it as the solution or giving a Karma. Thanks!

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@Alan_Chan - Are you sure your Splunk port is 8443??

 

0 Karma

Alan_Chan
Explorer

Splunk ES using 8000 port while SOAR using 8443 port

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@Alan_Chan - Here is what got to understand:

* You are using SOAR on 8443 port.

* You are trying to connect SOAR from Splunk ES as per this - https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/6.4.1/introducti...

 

If this is the case and if:

* you are entering the IP & credentials correct

* and there is no connectivity issue.

 

Then it is most likely SSL certificate validation issue. And your error also suggests the same thing.

VatsalJagani_0-1750928546326.png

 

You can follow the document to fix it - https://help.splunk.com/en/splunk-soar/soar-on-premises/administer-soar-on-premises/6.4.1/manage-spl...

* Please kindly understand SSL certificates well before you apply this on Production to avoid any issues.

 

I hope this helps!!! Kindly upvote if it does!!!

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...