Splunk SOAR

DNS error when logging in to Splunk SOAR instance deployed on an AWS EC2 instance

sschimper
Splunk Employee
Splunk Employee

Hi,

I have a simple AWS environment, and want to create an EC2 instance with the Splunk SOAR (On-premises) AMI from the Amazon Marketplace running on it.

I am following these instructions from the Splunk Docs.

The issue I am facing is that when I attempt to log in to the deployed SOAR instance (after giving it 20 mins to initialise), I receive an DNS error as shown on the screenshot below. I am using the public IP address from the AWS console.

Screenshot 2022-11-04 at 11.16.31.png

Has someone an idea? Thanks in advance for your help and support!

 

Labels (1)
0 Karma
1 Solution

sschimper
Splunk Employee
Splunk Employee

I fixed the issue. I was connecting to the web interface via HTTP and it should have been HTTPS. I guess, I automatically assumed it would be the same as with the Splunk Enterprise AMI, since it doesn't have HTTPS enabled by default.

View solution in original post

0 Karma

sschimper
Splunk Employee
Splunk Employee

I fixed the issue. I was connecting to the web interface via HTTP and it should have been HTTPS. I guess, I automatically assumed it would be the same as with the Splunk Enterprise AMI, since it doesn't have HTTPS enabled by default.

0 Karma
Get Updates on the Splunk Community!

New This Month in Splunk Observability Cloud - Metrics Usage Analytics, Enhanced K8s ...

The latest enhancements across the Splunk Observability portfolio deliver greater flexibility, better data and ...

Alerting Best Practices: How to Create Good Detectors

At their best, detectors and the alerts they trigger notify teams when applications aren’t performing as ...

Discover Powerful New Features in Splunk Cloud Platform: Enhanced Analytics, ...

Hey Splunky people! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2408. In this ...