<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is our Splunk 6.0.5 Universal Forwarder (HPUX) not contacting our Splunk 6.2.3 Deployment Server, even if connectivity exists. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-our-Splunk-6-0-5-Universal-Forwarder-HPUX-not-contacting/m-p/145774#M29723</link>
    <description>&lt;P&gt;Very good explanation &amp;amp; troubleshooting tips in this topic:&lt;BR /&gt;
&lt;A href="http://wiki.splunk.com/Community:Splunk2Splunk_SSL_DefaultCerts"&gt;http://wiki.splunk.com/Community:Splunk2Splunk_SSL_DefaultCerts&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Take a look at this error :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;06-09-2015 12:11:37.125 +0100 ERROR ServerConfig - No '$SplunkHome/splunkforwarder/etc/auth/server.pem' certificate found.  Splunkd communication will not work without this!
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;in your deployment setup, your universal forwarder is not properly exchanged the keys for authentication for communication,&lt;/P&gt;

&lt;P&gt;Copy the ''$SplunkHome/splunkforwarder/etc/auth/server.pem" from the deployment and paste in your deployment server under same path and restart.. then try again to reload the config from deployment to push the configs.&lt;/P&gt;</description>
    <pubDate>Thu, 11 Jun 2015 06:41:21 GMT</pubDate>
    <dc:creator>splunker12er</dc:creator>
    <dc:date>2015-06-11T06:41:21Z</dc:date>
    <item>
      <title>Why is our Splunk 6.0.5 Universal Forwarder (HPUX) not contacting our Splunk 6.2.3 Deployment Server, even if connectivity exists.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-our-Splunk-6-0-5-Universal-Forwarder-HPUX-not-contacting/m-p/145773#M29722</link>
      <description>&lt;P&gt;I have installed Splunk Universal forwarder 6.0.5 in HPUX  B.11.11 U 9000/800 box.&lt;/P&gt;

&lt;P&gt;We are using deployment server (Splunk 6.2.3) to push apps.&lt;/P&gt;

&lt;P&gt;But the HPUX box where we have installed splunk forwarder is not contacting our Deployment server.&lt;/P&gt;

&lt;P&gt;While starting splunk for the first time during installation, we are getting the below message.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Splunk needs access to the system random number generator to generate
security certificates.  Normally this is provided by the /dev/urandom
device which is not present or accessible on this system. To fix this
problem, either:
  * download the "HP-UX Strong Number Generator" application package
    from HP's website
  * or, if the openssl package is installed on the system make sure the
    "prngd" daemon is running.  This is controlled at system startup
    by the /etc/rc.config.d/prngd file.

Do you want to continue anyway [y/n]? y

This appears to be your first time running this version of Splunk.

Splunk&amp;gt; See your world.  Maybe wish you hadn't................................
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But splunk has started fine.&lt;/P&gt;

&lt;P&gt;We are getting below error messages in splunkd.log&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;06-09-2015 12:15:32.504 +0100 INFO  DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected
06-09-2015 12:15:34.360 +0100 ERROR HTTPClient - Should have gotten at least 3 tokens in status line, while getting response code.  Only got 0.
06-09-2015 12:15:34.360 +0100 INFO  HttpPubSubConnection - Secure HTTP POST failed: Unknown read error
06-09-2015 12:15:34.360 +0100 INFO  HttpPubSubConnection - Could not obtain connection, will retry after=78 seconds.
06-09-2015 12:15:44.524 +0100 INFO  DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected

06-09-2015 12:11:37.125 +0100 ERROR ServerConfig - No '$SplunkHome/splunkforwarder/etc/auth/server.pem' certificate found.  Splunkd communication will not work without this!
06-09-2015 12:11:47.657 +0100 ERROR HTTPServer - SSL context could not be created - error in cert or password is wrong
06-09-2015 12:11:47.657 +0100 ERROR HTTPServer - SSL will not be enabled
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Can anyone help us figure out why this Splunk universal forwarder is not contacting our Deployment server?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2015 13:23:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-our-Splunk-6-0-5-Universal-Forwarder-HPUX-not-contacting/m-p/145773#M29722</guid>
      <dc:creator>splunkn</dc:creator>
      <dc:date>2015-06-09T13:23:38Z</dc:date>
    </item>
    <item>
      <title>Re: Why is our Splunk 6.0.5 Universal Forwarder (HPUX) not contacting our Splunk 6.2.3 Deployment Server, even if connectivity exists.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-our-Splunk-6-0-5-Universal-Forwarder-HPUX-not-contacting/m-p/145774#M29723</link>
      <description>&lt;P&gt;Very good explanation &amp;amp; troubleshooting tips in this topic:&lt;BR /&gt;
&lt;A href="http://wiki.splunk.com/Community:Splunk2Splunk_SSL_DefaultCerts"&gt;http://wiki.splunk.com/Community:Splunk2Splunk_SSL_DefaultCerts&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Take a look at this error :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;06-09-2015 12:11:37.125 +0100 ERROR ServerConfig - No '$SplunkHome/splunkforwarder/etc/auth/server.pem' certificate found.  Splunkd communication will not work without this!
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;in your deployment setup, your universal forwarder is not properly exchanged the keys for authentication for communication,&lt;/P&gt;

&lt;P&gt;Copy the ''$SplunkHome/splunkforwarder/etc/auth/server.pem" from the deployment and paste in your deployment server under same path and restart.. then try again to reload the config from deployment to push the configs.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2015 06:41:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-our-Splunk-6-0-5-Universal-Forwarder-HPUX-not-contacting/m-p/145774#M29723</guid>
      <dc:creator>splunker12er</dc:creator>
      <dc:date>2015-06-11T06:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why is our Splunk 6.0.5 Universal Forwarder (HPUX) not contacting our Splunk 6.2.3 Deployment Server, even if connectivity exists.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-our-Splunk-6-0-5-Universal-Forwarder-HPUX-not-contacting/m-p/145775#M29724</link>
      <description>&lt;P&gt;splunker12er,&lt;BR /&gt;
Many thanks for your response, we have tried with copying ''$SplunkHome/splunk/etc/auth/server.pem from Deployment server to Universal forwarder, as in our case server.pem not found UF, instead of DS.&lt;BR /&gt;
However no luck.&lt;/P&gt;

&lt;P&gt;Do we need to do anything with enablesplunkdssl?&lt;BR /&gt;
Because we have crossed errors related to splunkdssl certificates? &lt;/P&gt;</description>
      <pubDate>Thu, 11 Jun 2015 14:52:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-our-Splunk-6-0-5-Universal-Forwarder-HPUX-not-contacting/m-p/145775#M29724</guid>
      <dc:creator>splunkn</dc:creator>
      <dc:date>2015-06-11T14:52:01Z</dc:date>
    </item>
  </channel>
</rss>

