<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DB Connect App stopped putting data in Splunk index after I updated my SSL certificates in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-Connect-App-stopped-putting-data-in-Splunk-index-after-I/m-p/266032#M30792</link>
    <description>&lt;P&gt;These logs are from forwarder ?? Seems like indexer and forwarder communication failed in 9997 port. forwarder unable to connect to indexer with 9997 port using SSL. Are you using 3rd party ssl / self sign ssl? anyhow could you please share the configs? &lt;/P&gt;

&lt;P&gt;Check the communication by: &lt;BR /&gt;
telnet  &lt;/P&gt;

&lt;P&gt;telnet x.x.x.x 997&lt;/P&gt;

&lt;P&gt;These are the few steps you can proceed to debug. &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;remove your ssl and validate the connection. &lt;/LI&gt;
&lt;LI&gt;if the step 1 works you have issue with your SSL configurations. &lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;My wild guess is your configurations on SSL is applied in forwarder but not indexer. since you are forcing forwarder to use SSL  to the indexer communication. Have you done anything in indexer?? &lt;/P&gt;

&lt;P&gt;&lt;A href="http://wiki.splunk.com/Community:Splunk2Splunk_SSL_SelfSignedCert_NewRootCA"&gt;http://wiki.splunk.com/Community:Splunk2Splunk_SSL_SelfSignedCert_NewRootCA&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;above is some old wiki page.. still you can refer the configurations. &lt;/P&gt;</description>
    <pubDate>Wed, 07 Sep 2016 14:06:17 GMT</pubDate>
    <dc:creator>vasanthmss</dc:creator>
    <dc:date>2016-09-07T14:06:17Z</dc:date>
    <item>
      <title>DB Connect App stopped putting data in Splunk index after I updated my SSL certificates</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-Connect-App-stopped-putting-data-in-Splunk-index-after-I/m-p/266026#M30786</link>
      <description>&lt;P&gt;My Splunk SSL certificates expired after the normal 3 year period. I have generated new SSL certificates which worked well with the forwarders running in the Linux OS. These forward data directly to the Splunk index.&lt;/P&gt;

&lt;P&gt;However, since the certificates expired, the Splunk index is still not receiving the data from the DB connect servers.&lt;/P&gt;

&lt;P&gt;What could be the root of this problem? How can I get my DB Connect App to start putting data in Splunk index? &lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2016 15:54:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-Connect-App-stopped-putting-data-in-Splunk-index-after-I/m-p/266026#M30786</guid>
      <dc:creator>princemagaisa</dc:creator>
      <dc:date>2016-09-06T15:54:44Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect App stopped putting data in Splunk index after I updated my SSL certificates</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-Connect-App-stopped-putting-data-in-Splunk-index-after-I/m-p/266027#M30787</link>
      <description>&lt;P&gt;in desparate need of an answer&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2016 16:06:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-Connect-App-stopped-putting-data-in-Splunk-index-after-I/m-p/266027#M30787</guid>
      <dc:creator>princemagaisa</dc:creator>
      <dc:date>2016-09-06T16:06:39Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect App stopped putting data in Splunk index after I updated my SSL certificates</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-Connect-App-stopped-putting-data-in-Splunk-index-after-I/m-p/266028#M30788</link>
      <description>&lt;P&gt;i am in desparate need of an answer, please help!&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2016 16:07:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-Connect-App-stopped-putting-data-in-Splunk-index-after-I/m-p/266028#M30788</guid>
      <dc:creator>princemagaisa</dc:creator>
      <dc:date>2016-09-06T16:07:35Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect App stopped putting data in Splunk index after I updated my SSL certificates</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-Connect-App-stopped-putting-data-in-Splunk-index-after-I/m-p/266029#M30789</link>
      <description>&lt;P&gt;check the below items, &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;splunk forwarder to indexer connection: if yes .... then look the internal logs of the forwarder you can find the issue else fix the connection problem. &lt;/LI&gt;
&lt;LI&gt;if there is no issue with the forwarder indexer communication - check for the dbconnect app's validate the connection details. &lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;post some more detail to answer further&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2016 16:46:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-Connect-App-stopped-putting-data-in-Splunk-index-after-I/m-p/266029#M30789</guid>
      <dc:creator>vasanthmss</dc:creator>
      <dc:date>2016-09-06T16:46:50Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect App stopped putting data in Splunk index after I updated my SSL certificates</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-Connect-App-stopped-putting-data-in-Splunk-index-after-I/m-p/266030#M30790</link>
      <description>&lt;P&gt;this is what i found on my logs&lt;BR /&gt;
09-06-2016 18:21:57.221 +0200 INFO  TcpOutputProc - Connection to x.x.x.x:9997 closed. Connection closed by server.&lt;BR /&gt;
09-06-2016 18:21:57.323 +0200 WARN  TcpOutputFd - Connect to x.x.x.x.x:9997 failed. Connection refused&lt;BR /&gt;
09-06-2016 18:21:57.323 +0200 ERROR TcpOutputFd - Connection to host=x.x.x.x.x:9997 failed&lt;BR /&gt;
09-06-2016 18:21:57.323 +0200 WARN  TcpOutputProc - Applying quarantine to ip=x.x.x.x=9997 _numberOfFailures=2&lt;BR /&gt;
09-06-2016 18:22:25.066 +0200 INFO  TcpOutputProc - Removing quarantine from idx=x.x.x.x:9997&lt;BR /&gt;
09-06-2016 18:22:25.067 +0200 INFO  TcpOutputProc - Connected to idx=x.x.x.x:9997&lt;BR /&gt;
09-06-2016 21:07:45.408 +0200 INFO  WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/splunk/var/log/splunk/dbx.log'.&lt;/P&gt;

&lt;P&gt;x.x.x.x refers to indexer IP&lt;/P&gt;

&lt;P&gt;Could it be SSL Certificate issues sinnce i did not apply the new certificates the DB Connect server&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 07:18:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-Connect-App-stopped-putting-data-in-Splunk-index-after-I/m-p/266030#M30790</guid>
      <dc:creator>princemagaisa</dc:creator>
      <dc:date>2016-09-07T07:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect App stopped putting data in Splunk index after I updated my SSL certificates</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-Connect-App-stopped-putting-data-in-Splunk-index-after-I/m-p/266031#M30791</link>
      <description>&lt;P&gt;this is what i found on my logs&lt;BR /&gt;
09-06-2016 18:21:57.221 +0200 INFO TcpOutputProc - Connection to x.x.x.x:9997 closed. Connection closed by server.&lt;BR /&gt;
09-06-2016 18:21:57.323 +0200 WARN TcpOutputFd - Connect to x.x.x.x.x:9997 failed. Connection refused&lt;BR /&gt;
09-06-2016 18:21:57.323 +0200 ERROR TcpOutputFd - Connection to host=x.x.x.x.x:9997 failed&lt;BR /&gt;
09-06-2016 18:21:57.323 +0200 WARN TcpOutputProc - Applying quarantine to ip=x.x.x.x=9997 _numberOfFailures=2&lt;BR /&gt;
09-06-2016 18:22:25.066 +0200 INFO TcpOutputProc - Removing quarantine from idx=x.x.x.x:9997&lt;BR /&gt;
09-06-2016 18:22:25.067 +0200 INFO TcpOutputProc - Connected to idx=x.x.x.x:9997&lt;BR /&gt;
09-06-2016 21:07:45.408 +0200 INFO WatchedFile - Checksum for seekptr didn't match, will re-read entire file='/opt/splunk/var/log/splunk/dbx.log'.&lt;/P&gt;

&lt;P&gt;x.x.x.x refers to indexer IP&lt;/P&gt;

&lt;P&gt;Could this also spring from SSL Certificate issues since i did not apply the new certificates the DB Connect server?&lt;/P&gt;

&lt;P&gt;DESPARATE, please help!&lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 12:45:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-Connect-App-stopped-putting-data-in-Splunk-index-after-I/m-p/266031#M30791</guid>
      <dc:creator>princemagaisa</dc:creator>
      <dc:date>2016-09-07T12:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: DB Connect App stopped putting data in Splunk index after I updated my SSL certificates</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-Connect-App-stopped-putting-data-in-Splunk-index-after-I/m-p/266032#M30792</link>
      <description>&lt;P&gt;These logs are from forwarder ?? Seems like indexer and forwarder communication failed in 9997 port. forwarder unable to connect to indexer with 9997 port using SSL. Are you using 3rd party ssl / self sign ssl? anyhow could you please share the configs? &lt;/P&gt;

&lt;P&gt;Check the communication by: &lt;BR /&gt;
telnet  &lt;/P&gt;

&lt;P&gt;telnet x.x.x.x 997&lt;/P&gt;

&lt;P&gt;These are the few steps you can proceed to debug. &lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;remove your ssl and validate the connection. &lt;/LI&gt;
&lt;LI&gt;if the step 1 works you have issue with your SSL configurations. &lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;My wild guess is your configurations on SSL is applied in forwarder but not indexer. since you are forcing forwarder to use SSL  to the indexer communication. Have you done anything in indexer?? &lt;/P&gt;

&lt;P&gt;&lt;A href="http://wiki.splunk.com/Community:Splunk2Splunk_SSL_SelfSignedCert_NewRootCA"&gt;http://wiki.splunk.com/Community:Splunk2Splunk_SSL_SelfSignedCert_NewRootCA&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;above is some old wiki page.. still you can refer the configurations. &lt;/P&gt;</description>
      <pubDate>Wed, 07 Sep 2016 14:06:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/DB-Connect-App-stopped-putting-data-in-Splunk-index-after-I/m-p/266032#M30792</guid>
      <dc:creator>vasanthmss</dc:creator>
      <dc:date>2016-09-07T14:06:17Z</dc:date>
    </item>
  </channel>
</rss>

