<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is it Possible to Send Data to Splunk Without SSL Handshake? in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-it-Possible-to-Send-Data-to-Splunk-Without-SSL-Handshake/m-p/703283#M3331</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I’m currently setting up a pipeline to send logs from AWS Kinesis Firehose to Splunk. I'm using Splunk’s Cloud &lt;STRONG&gt;Trial version &lt;/STRONG&gt;as the destination endpoint, and my goal is to send data without requiring an SSL handshake.&lt;/P&gt;&lt;P&gt;Here's a summary of my setup:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Service: AWS Kinesis Firehose&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Destination: Splunk Cloud Trail (using Splunk HEC URL)&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;STRONG&gt;Goal: Send data directly from Firehose to Splunk without SSL validation, if possible.&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;PRE&gt;"errorCode": "Splunk.SSLHandshake",&lt;BR /&gt;"errorMessage": "Could not connect to the HEC endpoint. Make sure that the certificate and the host are valid."&lt;/PRE&gt;&lt;P&gt;To troubleshoot, I also tested sending a record with the following command:&lt;/P&gt;&lt;PRE&gt;aws firehose put-record --delivery-stream-name FirehoseSplunkDeliveryStream \&lt;BR /&gt;--record='{"Data":"eyJldmVudCI6eyJrZXkxIjoidmFsdWUxIiwia2V5MiI6InZhbHVlMiJ9fQ=="}'&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;The SSL handshake error persists when connecting to the Splunk HEC endpoint.&lt;/P&gt;&lt;P&gt;Has anyone configured a similar setup, or is there a workaround to disable SSL validation for the Splunk endpoint? I'm new to splunk and just trying it out, any insights or suggestions would be greatly appreciated!&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
    <pubDate>Thu, 31 Oct 2024 19:00:40 GMT</pubDate>
    <dc:creator>rake</dc:creator>
    <dc:date>2024-10-31T19:00:40Z</dc:date>
    <item>
      <title>Is it Possible to Send Data to Splunk Without SSL Handshake?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-it-Possible-to-Send-Data-to-Splunk-Without-SSL-Handshake/m-p/703283#M3331</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I’m currently setting up a pipeline to send logs from AWS Kinesis Firehose to Splunk. I'm using Splunk’s Cloud &lt;STRONG&gt;Trial version &lt;/STRONG&gt;as the destination endpoint, and my goal is to send data without requiring an SSL handshake.&lt;/P&gt;&lt;P&gt;Here's a summary of my setup:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Service: AWS Kinesis Firehose&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Destination: Splunk Cloud Trail (using Splunk HEC URL)&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;&lt;STRONG&gt;Goal: Send data directly from Firehose to Splunk without SSL validation, if possible.&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;PRE&gt;"errorCode": "Splunk.SSLHandshake",&lt;BR /&gt;"errorMessage": "Could not connect to the HEC endpoint. Make sure that the certificate and the host are valid."&lt;/PRE&gt;&lt;P&gt;To troubleshoot, I also tested sending a record with the following command:&lt;/P&gt;&lt;PRE&gt;aws firehose put-record --delivery-stream-name FirehoseSplunkDeliveryStream \&lt;BR /&gt;--record='{"Data":"eyJldmVudCI6eyJrZXkxIjoidmFsdWUxIiwia2V5MiI6InZhbHVlMiJ9fQ=="}'&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;The SSL handshake error persists when connecting to the Splunk HEC endpoint.&lt;/P&gt;&lt;P&gt;Has anyone configured a similar setup, or is there a workaround to disable SSL validation for the Splunk endpoint? I'm new to splunk and just trying it out, any insights or suggestions would be greatly appreciated!&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 31 Oct 2024 19:00:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-it-Possible-to-Send-Data-to-Splunk-Without-SSL-Handshake/m-p/703283#M3331</guid>
      <dc:creator>rake</dc:creator>
      <dc:date>2024-10-31T19:00:40Z</dc:date>
    </item>
    <item>
      <title>Re: Is it Possible to Send Data to Splunk Without SSL Handshake?</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-it-Possible-to-Send-Data-to-Splunk-Without-SSL-Handshake/m-p/703286#M3332</link>
      <description>&lt;P&gt;&amp;nbsp;Hello &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273640"&gt;@rake&lt;/a&gt;&amp;nbsp;This could be the issue because you are on trial version (firehose has another endpoint) .&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Deploying this add-on to free trial Splunk Cloud deployments is not supported at this time.&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Refer:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/AddOns/released/Firehose/Installationoverview" target="_blank"&gt;https://docs.splunk.com/Documentation/AddOns/released/Firehose/Installationoverview&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;SPAN&gt;Note: Disabling SSL validation is not recommended for production environments..&lt;BR /&gt;&lt;BR /&gt;If this helps, please Upvote.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 31 Oct 2024 20:21:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/Is-it-Possible-to-Send-Data-to-Splunk-Without-SSL-Handshake/m-p/703286#M3332</guid>
      <dc:creator>sainag_splunk</dc:creator>
      <dc:date>2024-10-31T20:21:21Z</dc:date>
    </item>
  </channel>
</rss>

