Splunk Search

Why is HTTP is working while HTTPS is not?

graju89
Path Finder

Hi,

I tried to enable SSL on my Splunk instances. A few of them were successful. Some of them(specifically none of the heavy forwarders ) are not working after I enabled SSL. HTTP on those servers are working fine, which means i have no problem with firewall. I am not sure what am I missing here. Help is much appreciated.

Thanks

Tags (1)
0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

To enable SSL for your web interfaces, you need to have the following in web.conf (http://docs.splunk.com/Documentation/Splunk/latest/admin/Webconf)

[settings]
enableSplunkWebSSL = true

You will need to restart for this to take effect.

You can also do this via the GUI, as described at http://docs.splunk.com/Documentation/Splunk/7.2.0/Security/TurnonbasicencryptionwithSplunkWeb

0 Karma

graju89
Path Finder

Hi sduff,

I did that. After I enabled, I cant access the web GUI using https and http should not be working after enabled SSL. I tried netstat on the server the port is listening but the connection is not established. Also, I am seeing this issue only on heavy forwarders though.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...