Splunk Server Certificate expired while there is no Splunk config set in EDR
search cancel

Splunk Server Certificate expired while there is no Splunk config set in EDR

book

Article ID: 267277

calendar_today

Updated On:

Products

Endpoint Detection and Response

Issue/Introduction

You receive an error on the Symantec Endpoint Detection and Response (SEDR) appliance that states that the Splunk Server Certificate has expired, however no Splunk server is currently configured.

Environment

A SEDR appliance where the Splunk Integration was previously configured but has since been removed.

Cause

The certificate metadata remained after removal of the Splunk Implementation settings.

Resolution

In SEDR 4.8 functionality was added that allows for the proper removal of the Splunk Integration settings.  It is recommended that customers upgrade to SEDR 4.8 or newer in order to receive this fix.