<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic All Database Related Splunk indexes stopped working post update to 7.1.1 in Security</title>
    <link>https://community.splunk.com/t5/Security/All-Database-Related-Splunk-indexes-stopped-working-post-update/m-p/428092#M10093</link>
    <description>&lt;P&gt;We recently updated splunk to latest version of 7.1.1 post that update, the splunk database connections are all not working. We receive the below warnings in the Jbrige.log &lt;/P&gt;

&lt;P&gt;ERROR Java process returned error code 1! Error: Initializing Splunk context... Environment: SplunkEnvironment{SPLUNK_HOME=D:\Program Files\Splunk,SPLUNK_DB=D:\Program Files\Splunk\var\lib\splunk} Configuring Log4j... Exception in thread "main" com.splunk.config.SplunkConfigurationException: IO Error while reading configuration from Splunkd: javax.net.ssl.SSLException: Received fatal alert: protocol_version  at com.splunk.config.rest.RESTAdapter.request(RESTAdapter.java:199)     at com.splunk.config.rest.RESTAdapter.readConfig(RESTAdapter.java:207)  at com.splunk.config.cache.CachedConfigurationAdapter.readConfig(CachedConfigurationAdapter.java:32)    at com.splunk.config.cache.CachedConfigurationAdapter.readStanza(CachedConfigurationAdapter.java:40)    at com.splunk.env.SplunkContext.getConfigStanza(SplunkContext.java:313)     at com.splunk.env.SplunkContext.initialize(SplunkContext.java:128)  at com.splunk.bridge.JavaBridgeServer.main(JavaBridgeServer.java:34) Caused by: javax.net.ssl.SSLException: Received fatal alert: protocol_version  at com.sun.net.ssl.internal.ssl.Alerts.getSSLException(Unknown Source)  at com.sun.net.ssl.internal.ssl.Alerts.getSSLException(Unknown Source)  at com.sun.net.ssl.internal.ssl.SSLSocketImpl.recvAlert(Unknown Source)     at com.sun.net.ssl.internal.ssl.SSLSocketImpl.readRecord(Unknown Source)    at com.sun.net.ssl.internal.ssl.SSLSocketImpl.performInitialHandshake(Unknown Source)   at com.sun.net.ssl.internal.ssl.SSLSocketImpl.startHandshake(Unknown Source)    at com.sun.net.ssl.internal.ssl.SSLSocketImpl.startHandshake(Unknown Source)    at sun.net.&lt;A href="http://www.protocol.https.HttpsClient.afterConnect(Unknown" target="_blank"&gt;www.protocol.https.HttpsClient.afterConnect(Unknown&lt;/A&gt; Source)  at sun.net.&lt;A href="http://www.protocol.https.AbstractDelegateHttpsURLConnection.connect(Unknown" target="_blank"&gt;www.protocol.https.AbstractDelegateHttpsURLConnection.connect(Unknown&lt;/A&gt; Source)    at sun.net.&lt;A href="http://www.protocol.https.HttpsURLConnectionImpl.connect(Unknown" target="_blank"&gt;www.protocol.https.HttpsURLConnectionImpl.connect(Unknown&lt;/A&gt; Source)    at com.splunk.rest.Splunkd.request(Splunkd.java:216)    at com.splunk.rest.Splunkd.request(Splunkd.java:102)    at com.splunk.config.rest.RESTAdapter.request(RESTAdapter.java:197)     ... 6 more &lt;/P&gt;

&lt;P&gt;Splunkd.log shows the below message:&lt;/P&gt;

&lt;P&gt;07-06-2018 12:36:17.089 +0100 WARN  SSLCommon - Received fatal SSL3 alert. ssl_state='SSLv3 read client hello C', alert_description='protocol version'.&lt;BR /&gt;
07-06-2018 12:36:17.089 +0100 WARN  HttpListener - Socket error from 127.0.0.1 while idling: error:1408A10B:SSL routines:ssl3_get_client_hello:wrong version number&lt;/P&gt;

&lt;P&gt;We are using JRE6 and splunk DBConnect version 1. the JBridge Server status in the splunk shows as loading.. &lt;/P&gt;

&lt;P&gt;Please can someone help.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 20:20:45 GMT</pubDate>
    <dc:creator>karthicksamy</dc:creator>
    <dc:date>2020-09-29T20:20:45Z</dc:date>
    <item>
      <title>All Database Related Splunk indexes stopped working post update to 7.1.1</title>
      <link>https://community.splunk.com/t5/Security/All-Database-Related-Splunk-indexes-stopped-working-post-update/m-p/428092#M10093</link>
      <description>&lt;P&gt;We recently updated splunk to latest version of 7.1.1 post that update, the splunk database connections are all not working. We receive the below warnings in the Jbrige.log &lt;/P&gt;

&lt;P&gt;ERROR Java process returned error code 1! Error: Initializing Splunk context... Environment: SplunkEnvironment{SPLUNK_HOME=D:\Program Files\Splunk,SPLUNK_DB=D:\Program Files\Splunk\var\lib\splunk} Configuring Log4j... Exception in thread "main" com.splunk.config.SplunkConfigurationException: IO Error while reading configuration from Splunkd: javax.net.ssl.SSLException: Received fatal alert: protocol_version  at com.splunk.config.rest.RESTAdapter.request(RESTAdapter.java:199)     at com.splunk.config.rest.RESTAdapter.readConfig(RESTAdapter.java:207)  at com.splunk.config.cache.CachedConfigurationAdapter.readConfig(CachedConfigurationAdapter.java:32)    at com.splunk.config.cache.CachedConfigurationAdapter.readStanza(CachedConfigurationAdapter.java:40)    at com.splunk.env.SplunkContext.getConfigStanza(SplunkContext.java:313)     at com.splunk.env.SplunkContext.initialize(SplunkContext.java:128)  at com.splunk.bridge.JavaBridgeServer.main(JavaBridgeServer.java:34) Caused by: javax.net.ssl.SSLException: Received fatal alert: protocol_version  at com.sun.net.ssl.internal.ssl.Alerts.getSSLException(Unknown Source)  at com.sun.net.ssl.internal.ssl.Alerts.getSSLException(Unknown Source)  at com.sun.net.ssl.internal.ssl.SSLSocketImpl.recvAlert(Unknown Source)     at com.sun.net.ssl.internal.ssl.SSLSocketImpl.readRecord(Unknown Source)    at com.sun.net.ssl.internal.ssl.SSLSocketImpl.performInitialHandshake(Unknown Source)   at com.sun.net.ssl.internal.ssl.SSLSocketImpl.startHandshake(Unknown Source)    at com.sun.net.ssl.internal.ssl.SSLSocketImpl.startHandshake(Unknown Source)    at sun.net.&lt;A href="http://www.protocol.https.HttpsClient.afterConnect(Unknown" target="_blank"&gt;www.protocol.https.HttpsClient.afterConnect(Unknown&lt;/A&gt; Source)  at sun.net.&lt;A href="http://www.protocol.https.AbstractDelegateHttpsURLConnection.connect(Unknown" target="_blank"&gt;www.protocol.https.AbstractDelegateHttpsURLConnection.connect(Unknown&lt;/A&gt; Source)    at sun.net.&lt;A href="http://www.protocol.https.HttpsURLConnectionImpl.connect(Unknown" target="_blank"&gt;www.protocol.https.HttpsURLConnectionImpl.connect(Unknown&lt;/A&gt; Source)    at com.splunk.rest.Splunkd.request(Splunkd.java:216)    at com.splunk.rest.Splunkd.request(Splunkd.java:102)    at com.splunk.config.rest.RESTAdapter.request(RESTAdapter.java:197)     ... 6 more &lt;/P&gt;

&lt;P&gt;Splunkd.log shows the below message:&lt;/P&gt;

&lt;P&gt;07-06-2018 12:36:17.089 +0100 WARN  SSLCommon - Received fatal SSL3 alert. ssl_state='SSLv3 read client hello C', alert_description='protocol version'.&lt;BR /&gt;
07-06-2018 12:36:17.089 +0100 WARN  HttpListener - Socket error from 127.0.0.1 while idling: error:1408A10B:SSL routines:ssl3_get_client_hello:wrong version number&lt;/P&gt;

&lt;P&gt;We are using JRE6 and splunk DBConnect version 1. the JBridge Server status in the splunk shows as loading.. &lt;/P&gt;

&lt;P&gt;Please can someone help.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:20:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/All-Database-Related-Splunk-indexes-stopped-working-post-update/m-p/428092#M10093</guid>
      <dc:creator>karthicksamy</dc:creator>
      <dc:date>2020-09-29T20:20:45Z</dc:date>
    </item>
  </channel>
</rss>

