<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Handshake and socket error in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Handshake-and-socket-error/m-p/113398#M23739</link>
    <description>&lt;P&gt;&lt;EM&gt;OS for forwarder: Windows Server 2012&lt;/EM&gt;&lt;BR /&gt;
&lt;EM&gt;Splunk + Universal Forwarder version: 6&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;I'm trying to get my Universal Forwarder to contact the deployment server. The only "change" I have done during the installation is setting the deployment server in the msiexec.exe.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;C:\Program Files\SplunkUniversalForwarder\etc\system\local\deploymentclient.conf:&lt;/STRONG&gt;&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;[target-broker:deploymentServer]&lt;BR /&gt;
targetUri = server:port&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;&lt;STRONG&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd.log:&lt;/STRONG&gt;&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;10-24-2013 15:46:00.722 +0200 INFO  HttpPubSubConnection - Secure HTTP POST failed: Connect to=server:port timed out; exceeded 5sec&lt;BR /&gt;
10-24-2013 15:46:00.722 +0200 INFO  HttpPubSubConnection - Could not obtain connection, will retry after=56 seconds.&lt;BR /&gt;
10-24-2013 15:46:08.584 +0200 INFO  DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;BR /&gt;
10-24-2013 15:46:20.597 +0200 INFO  DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;BR /&gt;
10-24-2013 15:46:32.609 +0200 INFO  DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;BR /&gt;
10-24-2013 15:46:44.621 +0200 INFO  DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;BR /&gt;
10-24-2013 15:46:56.634 +0200 INFO  DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;&lt;STRONG&gt;Log from the Splunk server&lt;/STRONG&gt;&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;10-24-2013 12:33:42.634 +0200 WARN  HttpListener - Socket error from X.X.X.X while idling: error:1407609C:SSL routines:SSL23_GET_CLIENT_HELLO:http request&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Just for clearity: I can not see my client trying to phone home in under Forwarder management.&lt;/P&gt;

&lt;P&gt;Have I left out something important in my forwarder configuration? Some suggestions on what I'm doing wrong?&lt;/P&gt;</description>
    <pubDate>Thu, 24 Oct 2013 14:05:56 GMT</pubDate>
    <dc:creator>drberg</dc:creator>
    <dc:date>2013-10-24T14:05:56Z</dc:date>
    <item>
      <title>Handshake and socket error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Handshake-and-socket-error/m-p/113398#M23739</link>
      <description>&lt;P&gt;&lt;EM&gt;OS for forwarder: Windows Server 2012&lt;/EM&gt;&lt;BR /&gt;
&lt;EM&gt;Splunk + Universal Forwarder version: 6&lt;/EM&gt;&lt;/P&gt;

&lt;P&gt;I'm trying to get my Universal Forwarder to contact the deployment server. The only "change" I have done during the installation is setting the deployment server in the msiexec.exe.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;C:\Program Files\SplunkUniversalForwarder\etc\system\local\deploymentclient.conf:&lt;/STRONG&gt;&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;[target-broker:deploymentServer]&lt;BR /&gt;
targetUri = server:port&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;&lt;STRONG&gt;C:\Program Files\SplunkUniversalForwarder\var\log\splunk\splunkd.log:&lt;/STRONG&gt;&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;10-24-2013 15:46:00.722 +0200 INFO  HttpPubSubConnection - Secure HTTP POST failed: Connect to=server:port timed out; exceeded 5sec&lt;BR /&gt;
10-24-2013 15:46:00.722 +0200 INFO  HttpPubSubConnection - Could not obtain connection, will retry after=56 seconds.&lt;BR /&gt;
10-24-2013 15:46:08.584 +0200 INFO  DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;BR /&gt;
10-24-2013 15:46:20.597 +0200 INFO  DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;BR /&gt;
10-24-2013 15:46:32.609 +0200 INFO  DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;BR /&gt;
10-24-2013 15:46:44.621 +0200 INFO  DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;BR /&gt;
10-24-2013 15:46:56.634 +0200 INFO  DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;&lt;STRONG&gt;Log from the Splunk server&lt;/STRONG&gt;&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;10-24-2013 12:33:42.634 +0200 WARN  HttpListener - Socket error from X.X.X.X while idling: error:1407609C:SSL routines:SSL23_GET_CLIENT_HELLO:http request&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;Just for clearity: I can not see my client trying to phone home in under Forwarder management.&lt;/P&gt;

&lt;P&gt;Have I left out something important in my forwarder configuration? Some suggestions on what I'm doing wrong?&lt;/P&gt;</description>
      <pubDate>Thu, 24 Oct 2013 14:05:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Handshake-and-socket-error/m-p/113398#M23739</guid>
      <dc:creator>drberg</dc:creator>
      <dc:date>2013-10-24T14:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: Handshake and socket error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Handshake-and-socket-error/m-p/113399#M23740</link>
      <description>&lt;P&gt;Well this is embarassing. Turns out I had the wrong url to the deployment server. It's all good now.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Oct 2013 09:18:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Handshake-and-socket-error/m-p/113399#M23740</guid>
      <dc:creator>drberg</dc:creator>
      <dc:date>2013-10-25T09:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: Handshake and socket error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Handshake-and-socket-error/m-p/113400#M23741</link>
      <description>&lt;P&gt;Same issue i am facing , and i also checked all urls. &lt;/P&gt;

&lt;P&gt;Please help me on this &lt;/P&gt;</description>
      <pubDate>Sun, 10 Nov 2013 12:54:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Handshake-and-socket-error/m-p/113400#M23741</guid>
      <dc:creator>rameshlpatel</dc:creator>
      <dc:date>2013-11-10T12:54:40Z</dc:date>
    </item>
    <item>
      <title>Re: Handshake and socket error</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Handshake-and-socket-error/m-p/113401#M23742</link>
      <description>&lt;P&gt;Maybe it's a firewall in the route to the deployment server?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Nov 2013 08:35:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Handshake-and-socket-error/m-p/113401#M23742</guid>
      <dc:creator>drberg</dc:creator>
      <dc:date>2013-11-11T08:35:55Z</dc:date>
    </item>
  </channel>
</rss>

