# Splunk logging with HTTPS requires client certificate

**URL:** <https://forums.suse.com/t/splunk-logging-with-https-requires-client-certificate/14147>\
**Category:** SUSE Rancher Prime\
**Created:** [May 2, 2019, 7:01pm UTC](https://forums.suse.com/t/splunk-logging-with-https-requires-client-certificate/14147 "2019-05-02T19:01:18Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![shubbard343](https://avatars.discourse-cdn.com/v4/letter/s/47e85d/32.png) [@shubbard343](https://forums.suse.com/u/shubbard343)\
**Post date:** [May 2, 2019, 7:01pm UTC](https://forums.suse.com/t/splunk-logging-with-https-requires-client-certificate/14147/1 "2019-05-02T19:01:18Z")

</div>

In Rancher 2.2, there apparently was a change to how Splunk logging is configured. If your Splunk endpoint starts with `https://`, then the SSL configuration opens up text boxes for Client key and certificate. A client cert is not required to use the Splunk HEC, so why does Rancher now require it? It was not a requirement in 2.1 and it was working fine without client certs.

---

<div class="post-metadata">

**Author:** ![shubbard343](https://avatars.discourse-cdn.com/v4/letter/s/47e85d/32.png) [@shubbard343](https://forums.suse.com/u/shubbard343)\
**Post date:** [May 7, 2019, 9:37pm UTC](https://forums.suse.com/t/splunk-logging-with-https-requires-client-certificate/14147/2 "2019-05-07T21:37:28Z")

</div>

It turns out that the problem was related to SSL inspection blocking the Catalog from fetching the logging containers. [This](http://forums.suse.com/t/catalog-not-loading-behind-corporate-proxy-with-ssl-inspection/11291/3) was the solution to get logging to work.
