<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSL error with new version of nozomi addon in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/SSL-error-with-new-version-of-nozomi-addon/m-p/690694#M114913</link>
    <description>&lt;P&gt;I suspect that they have made some changes to the TA add-on code and python scripts&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;universal&lt;/SPAN&gt;&lt;SPAN&gt;_session.py&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I would contact them directly and see if you can get any further information. Disabling comes with security risks,&amp;nbsp;&amp;nbsp;and most likely done within the python code. But I understand you have self signed ones,&amp;nbsp; and should have options, so seeking their advise might be the best cause of action, hopefully they can get the TA developer to give you further help.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="mailto:support@nozominetworks.com" target="_blank"&gt;support@nozominetworks.com&lt;/A&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Jun 2024 07:33:36 GMT</pubDate>
    <dc:creator>deepakc</dc:creator>
    <dc:date>2024-06-14T07:33:36Z</dc:date>
    <item>
      <title>SSL error with new version of nozomi addon</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SSL-error-with-new-version-of-nozomi-addon/m-p/690658#M114903</link>
      <description>&lt;P&gt;Hi, I'm not able to integrate SPlunk with Nozomi, with the available app (Nozomi Networks Universal Add-on), on the other hand I've tested the legacy addon and receive the alerys/assets but not with full info.&lt;/P&gt;&lt;P&gt;The server (Nozomi Guardian) is self-signed.&lt;/P&gt;&lt;P&gt;After configuring the latest version and setting up the inputs for receiving alerts, asset etc. There's no data being received in the index, and from the splunk logs I see the following:&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;SPAN class=""&gt;06-13-2024&lt;/SPAN&gt; &lt;SPAN class=""&gt;21:23:01.529&lt;/SPAN&gt; +&lt;SPAN class=""&gt;0200&lt;/SPAN&gt; &lt;SPAN class=""&gt;ERROR&lt;/SPAN&gt; &lt;SPAN class=""&gt;ExecProcessor&lt;/SPAN&gt; [&lt;SPAN class=""&gt;3854374&lt;/SPAN&gt; &lt;SPAN class=""&gt;ExecProcessor&lt;/SPAN&gt;] &lt;SPAN class=""&gt;-&lt;/SPAN&gt; &lt;SPAN class=""&gt;message&lt;/SPAN&gt; &lt;SPAN class=""&gt;from&lt;/SPAN&gt; "&lt;SPAN class=""&gt;/opt/splunk/bin/python3.7&lt;/SPAN&gt; &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;/opt/splunk/etc/apps/TA-nozomi-networks-universal-add-on/bin/universal&lt;/SPAN&gt;_session.py&lt;/SPAN&gt;" &lt;SPAN class=""&gt;HTTPSConnectionPool&lt;/SPAN&gt;(&lt;SPAN class=""&gt;host=&lt;/SPAN&gt;'&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;192.168.1.4&lt;/SPAN&gt;&lt;/SPAN&gt;', &lt;SPAN class=""&gt;port=443&lt;/SPAN&gt;)&lt;SPAN class=""&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;Max&lt;/SPAN&gt; &lt;SPAN class=""&gt;retries&lt;/SPAN&gt; &lt;SPAN class=""&gt;exceeded&lt;/SPAN&gt; &lt;SPAN class=""&gt;with&lt;/SPAN&gt; &lt;SPAN class=""&gt;url:&lt;/SPAN&gt; &lt;SPAN class=""&gt;/api/open/sign_in&lt;/SPAN&gt; (&lt;SPAN class=""&gt;Caused&lt;/SPAN&gt; &lt;SPAN class=""&gt;by&lt;/SPAN&gt; &lt;SPAN class=""&gt;SSLError&lt;/SPAN&gt;(&lt;SPAN class=""&gt;SSLCertVerificationError&lt;/SPAN&gt;(&lt;SPAN class=""&gt;1&lt;/SPAN&gt;, '[&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;SSL&lt;/SPAN&gt;:&lt;/SPAN&gt; &lt;SPAN class=""&gt;CERTIFICATE_VERIFY_FAILED&lt;/SPAN&gt;] &lt;SPAN class=""&gt;certificate&lt;/SPAN&gt; &lt;SPAN class=""&gt;verify&lt;/SPAN&gt; &lt;SPAN class=""&gt;failed:&lt;/SPAN&gt; &lt;SPAN class=""&gt;self&lt;/SPAN&gt; &lt;SPAN class=""&gt;signed&lt;/SPAN&gt; &lt;SPAN class=""&gt;certificate&lt;/SPAN&gt; (&lt;SPAN class=""&gt;_&lt;SPAN class=""&gt;ssl&lt;/SPAN&gt;.c:1106&lt;/SPAN&gt;)')))&lt;/P&gt;&lt;P&gt;I tought the solution could be by just disabling the ssl verification, but then why the legacy addon is working fine but the new version is not? In case I need to disable SSL verification, would like to know where is the right file and parameter.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2024 19:28:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SSL-error-with-new-version-of-nozomi-addon/m-p/690658#M114903</guid>
      <dc:creator>Aqibrehman1</dc:creator>
      <dc:date>2024-06-13T19:28:05Z</dc:date>
    </item>
    <item>
      <title>Re: SSL error with new version of nozomi addon</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/SSL-error-with-new-version-of-nozomi-addon/m-p/690694#M114913</link>
      <description>&lt;P&gt;I suspect that they have made some changes to the TA add-on code and python scripts&amp;nbsp;&amp;nbsp;&lt;SPAN class=""&gt;universal&lt;/SPAN&gt;&lt;SPAN&gt;_session.py&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I would contact them directly and see if you can get any further information. Disabling comes with security risks,&amp;nbsp;&amp;nbsp;and most likely done within the python code. But I understand you have self signed ones,&amp;nbsp; and should have options, so seeking their advise might be the best cause of action, hopefully they can get the TA developer to give you further help.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="mailto:support@nozominetworks.com" target="_blank"&gt;support@nozominetworks.com&lt;/A&gt;&lt;SPAN&gt;.&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 07:33:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/SSL-error-with-new-version-of-nozomi-addon/m-p/690694#M114913</guid>
      <dc:creator>deepakc</dc:creator>
      <dc:date>2024-06-14T07:33:36Z</dc:date>
    </item>
  </channel>
</rss>

