Azure / Azure/azure-quickstart-templates

Splunk on Ubuntu: Ingestion Endpoint Authentication

Open
#2,044 5 comments 0 reactions 0 assignees View on GitHub
question
Dominant language
Bicep
Stars
14.9k
Forks
16.2k
Avg merge
6d 21h
Merged PRs (30d)
6

Description

Team,

we have set up a splunk cluster using the following template:
https://github.com/Azure/azure-quickstart-templates/tree/master/splunk-on-ubuntu

But we were into issues when trying to authenticate the ingestion endpoint. On setting up SSL, the error that we are getting: Connect to **.**.**.** failed. No connection could be made because the target machine actively refused it.

May we know if we can use the 9997 for secured TCP (SSL) receiver traffic?

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the Splunk on Ubuntu template linked in the issue and inspect its SSL and ingestion receiver configuration, focusing on port 9997. Reproduce the connection refusal and determine whether secured TCP receiver traffic is supported there; done means the supported configuration or required correction is clearly documented.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure, ubuntu
Domain
cloud, devops
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.