Error BFX-SPLK-404: Issues with BigFix-Splunk Integration

Hello Everyone,

I’m in the process of integrating BigFix with Splunk to improve our monitoring and reporting capabilities. I have been following the guide available -https://www.bigfix.me/analysis/details/2994522, https://github.com/codingWithJimmy/TA-bigfix/splunk , https://splunkbase.splunk.com/app/4973, but I’ve run into a significant roadblock.

After completing the integration steps, I expected to see the logs from BigFix flowing into Splunk, but that’s not happening. Instead, I’m encountering an error message in the Splunk interface that says -: “Connection to BigFix failed. Unable to establish a link with the specified parameters. Please verify the configuration.”

Error Code: BFX-SPLK-404

I’ve double-checked my configuration settings, compared them with the instructions in the link above, and everything seems to be correct. The firewall rules are in place, and all the necessary permissions have been granted.

Has anyone experienced this specific issue or a similar one while integrating BigFix with Splunk? Are there known solutions or workarounds that you could share with me? If there’s a need to modify specific configuration files or apply a particular patch, could you please guide me through the process?

Thanks in adavnce!

The error returned “Connection to BigFix failed” along with the 404 in the error code suggests that the device where the add-on is installed cannot communicate with the BigFix Server. Are you able to verify and validate network communication outside of the add-on? For instance, are you able to ping the URL you specified for the BigFix Server from the device and/or telnet to it on the BigFix port?