Getting Data In

Splunk DB Connect and reverse proxy

kenmcgarrahan
Explorer

Running Splunk (in trial mode) behind a reverse proxy (wiki.splunk.com/Community:SplunkBehindAProxy) and have a problem with the DB Connect app not using the configured context root for selected actions.

In ${SPLUNK_HOME}/system/local/web.conf:

[settings]
root_endpoint = /splunkv
tools.proxy.on = True

In the DB Connect configuration in the web console, the URL associated with the 'Database Connections in Splunk Manager' button lacks the '/splunkv'/ context. A 'hover' over indicates the URL is '//myhost/manager/dbx/dbx/databases', an invalid context which displays a 404 error when clicked. Manually correcting the URL to include the 'splunkv' context ('//myhost/splunkv/manager/dbx/dbx/databases') displays the page correctly and allows interaction with the DB Connect configuration.

Is there a corresponding DB Connect proxy setting which corrects this error? Is there a general solution which ensures adherence to the root_endpoint value in web.conf?

0 Karma

araitz
Splunk Employee
Splunk Employee

Yes, there are a few places we've recently identified that do not respect custom root endpoints. There aren't any quick workarounds available yet.

Would it be possible for you to open a support case so we can notify you when there is a fix available? I'll try to remember to update here as well.

araitz
Splunk Employee
Splunk Employee

Sounds good, appreciate it. If I can get a workaround or provide an update here, I will do so.

0 Karma

kenmcgarrahan
Explorer

No valid support contract (yet), so opening a support case isn't possible.

When production licenses are procured, I can add the support case.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...