Splunk Search

Why is HTTP is working while HTTPS is not?

graju89
Path Finder

Hi,

I tried to enable SSL on my Splunk instances. A few of them were successful. Some of them(specifically none of the heavy forwarders ) are not working after I enabled SSL. HTTP on those servers are working fine, which means i have no problem with firewall. I am not sure what am I missing here. Help is much appreciated.

Thanks

Tags (1)
0 Karma

sduff_splunk
Splunk Employee
Splunk Employee

To enable SSL for your web interfaces, you need to have the following in web.conf (http://docs.splunk.com/Documentation/Splunk/latest/admin/Webconf)

[settings]
enableSplunkWebSSL = true

You will need to restart for this to take effect.

You can also do this via the GUI, as described at http://docs.splunk.com/Documentation/Splunk/7.2.0/Security/TurnonbasicencryptionwithSplunkWeb

0 Karma

graju89
Path Finder

Hi sduff,

I did that. After I enabled, I cant access the web GUI using https and http should not be working after enabled SSL. I tried netstat on the server the port is listening but the connection is not established. Also, I am seeing this issue only on heavy forwarders though.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Rounding off the Splunk Dashboard Contest

What does a contest-winning Splunk dashboard look like? In this case, it isn't in a browser tab at all. It ...

A Four Part Event Series: AI + Observability: AI Agents, LLMs, Apps, & Infrastructure

AI + Observability: AI Agents, LLMs, Apps, & Infrastructure The rapid evolution of artificial intelligence ...

Splunk Technical Support Is Moving to Cisco Support Tools

Introduction Splunk technical support is transitioning to Cisco’s support environment. This change brings ...