I finally have an answer for this problem that may help you.
In our case, as per my comment, the issue is that our production Splunk search head has no Internet facing services. No DNS, no HTTPS. Everything must be done through an authenticated proxy for HTTP/HTTPS.
In order to get the Box for Splunk App working, I did the following:
Install the Box for Splunk App
Edit $SPLUNK_HOME/etc/splunk-launch.conf to contain the following:
HTTP_PROXY = http://127.0.0.1:3128
HTTPS_PROXY = http://127.0.0.1:3128
Install "cntlm" from http://cntlm.sourceforge.net
Configure cntlm to perform NTLMv2 authentication via our proxy and listen on 3128
Restart Splunk
From there, things just worked.
The initial problem I had was that the Splunk documentation says that the HTTP_PROXY requires just an IP address; however, that didn't work. It needed the actual "http://" as well -- now, in theory, you might be able to use HTTP_PROXY=http://user:pass@proxy.address:port , but I haven't tried that, as leaving a password in a conf file like this isn't a good idea...
... View more