<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Received fatal SSL3 alert in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Received-fatal-SSL3-alert/m-p/328607#M60974</link>
    <description>&lt;P&gt;This occurred due to the network peripherals failing when trying to communicate to the AWS Instances.&lt;/P&gt;

&lt;P&gt;The data from our infrastructure to AWS was being sent in size (2 TBs per day) that the peripheral cannot tolerate the traffic any longer and ended up fluctuating and rebooting the devices.&lt;/P&gt;

&lt;P&gt;The N/W team then maximized the data that can be sent across and that fixed the issue. &lt;/P&gt;</description>
    <pubDate>Wed, 24 May 2017 11:47:10 GMT</pubDate>
    <dc:creator>vr2312</dc:creator>
    <dc:date>2017-05-24T11:47:10Z</dc:date>
    <item>
      <title>Received fatal SSL3 alert</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Received-fatal-SSL3-alert/m-p/328605#M60972</link>
      <description>&lt;P&gt;I am unable to connect to my Indexer ClusterMaster on Cloud on Port 8000. &lt;/P&gt;

&lt;P&gt;On checking splunkd.log, i can observe some WARN messages as below.&lt;/P&gt;

&lt;P&gt;Not sure if this is related.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;03-01-2017 07:26:47.474 -0500 WARN  SSLCommon - Received fatal SSL3 alert. ssl_state='SSLv3 read client key exchange A', alert_description='unknown CA'.&lt;BR /&gt;
03-01-2017 07:26:47.474 -0500 WARN  HttpListener - Socket error from 127.0.0.1 while idling: error:14094418:SSL routines:ssl3_read_bytes:tlsv1 alert unknown ca&lt;BR /&gt;
03-01-2017 07:26:47.475 -0500 WARN  SSLCommon - Received fatal SSL3 alert. ssl_state='SSLv3 read client key exchange A', alert_description='unknown CA'.&lt;BR /&gt;
03-01-2017 07:26:47.475 -0500 WARN  HttpListener - Socket error from 127.0.0.1 while idling: error:14094418:SSL routines:ssl3_read_bytes:tlsv1 alert unknown ca&lt;BR /&gt;
03-01-2017 07:26:47.475 -0500 WARN  SSLCommon - Received fatal SSL3 alert. ssl_state='SSLv3 read client key exchange A', alert_description='unknown CA'.&lt;BR /&gt;
03-01-2017 07:26:47.475 -0500 WARN  HttpListener - Socket error from 127.0.0.1 while idling: error:14094418:SSL routines:ssl3_read_bytes:tlsv1 alert unknown ca&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 13:03:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Received-fatal-SSL3-alert/m-p/328605#M60972</guid>
      <dc:creator>vr2312</dc:creator>
      <dc:date>2020-09-29T13:03:03Z</dc:date>
    </item>
    <item>
      <title>Re: Received fatal SSL3 alert</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Received-fatal-SSL3-alert/m-p/328606#M60973</link>
      <description>&lt;P&gt;Were you able to resolve this? I'm seeing it in one of my environments too.&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 11:37:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Received-fatal-SSL3-alert/m-p/328606#M60973</guid>
      <dc:creator>napomokoetle</dc:creator>
      <dc:date>2017-05-24T11:37:21Z</dc:date>
    </item>
    <item>
      <title>Re: Received fatal SSL3 alert</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Received-fatal-SSL3-alert/m-p/328607#M60974</link>
      <description>&lt;P&gt;This occurred due to the network peripherals failing when trying to communicate to the AWS Instances.&lt;/P&gt;

&lt;P&gt;The data from our infrastructure to AWS was being sent in size (2 TBs per day) that the peripheral cannot tolerate the traffic any longer and ended up fluctuating and rebooting the devices.&lt;/P&gt;

&lt;P&gt;The N/W team then maximized the data that can be sent across and that fixed the issue. &lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 11:47:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Received-fatal-SSL3-alert/m-p/328607#M60974</guid>
      <dc:creator>vr2312</dc:creator>
      <dc:date>2017-05-24T11:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: Received fatal SSL3 alert</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Received-fatal-SSL3-alert/m-p/328608#M60975</link>
      <description>&lt;P&gt;@napomokoetle&lt;/P&gt;

&lt;P&gt;Please check whether the connectivity between the instances is normal.&lt;/P&gt;

&lt;P&gt;In my case, the connectivity was majorly impacted due from the N/W end.&lt;/P&gt;

&lt;P&gt;Once that was resolved, the issue subsided.&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 11:50:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Received-fatal-SSL3-alert/m-p/328608#M60975</guid>
      <dc:creator>vr2312</dc:creator>
      <dc:date>2017-05-24T11:50:30Z</dc:date>
    </item>
    <item>
      <title>Re: Received fatal SSL3 alert</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Received-fatal-SSL3-alert/m-p/328609#M60976</link>
      <description>&lt;P&gt;Even though I'm getting these ssl errors on the Splunk proxy, it seems the data collections from the Splunk Universal Forwarder agents are still happening successfully.&lt;BR /&gt;
Also, I see that the SSL3 errors only started after I upgraded the Splunk servers to v6.6. Any one know how to eradicate these ssl3 errors.&lt;/P&gt;</description>
      <pubDate>Wed, 24 May 2017 18:50:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Received-fatal-SSL3-alert/m-p/328609#M60976</guid>
      <dc:creator>napomokoetle</dc:creator>
      <dc:date>2017-05-24T18:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: Received fatal SSL3 alert</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Received-fatal-SSL3-alert/m-p/328610#M60977</link>
      <description>&lt;P&gt;@napomokoetle&lt;/P&gt;

&lt;P&gt;Please open a new "question" and post it there for users to look into it and respond.&lt;/P&gt;</description>
      <pubDate>Thu, 25 May 2017 11:04:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Received-fatal-SSL3-alert/m-p/328610#M60977</guid>
      <dc:creator>vr2312</dc:creator>
      <dc:date>2017-05-25T11:04:45Z</dc:date>
    </item>
  </channel>
</rss>

