<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Syslog + SSL connection logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-SSL-connection-logs/m-p/445324#M77500</link>
    <description>&lt;P&gt;Sending syslog directly to Splunk is against best practice. You should send it to a syslog server like Rsyslog or Syslog-ng. Regardless, you would have to install certificates on the receiving host, otherwise handshake will fail.&lt;/P&gt;

&lt;P&gt;Check out the answer here: &lt;A href="https://answers.splunk.com/answers/658055/setup-secure-encrypted-syslog.html"&gt;https://answers.splunk.com/answers/658055/setup-secure-encrypted-syslog.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;But the splunkd.log would have any errors. /opt/splunk/var/log/splunk |grep -i error&lt;/P&gt;</description>
    <pubDate>Wed, 20 Mar 2019 17:40:40 GMT</pubDate>
    <dc:creator>bcyates</dc:creator>
    <dc:date>2019-03-20T17:40:40Z</dc:date>
    <item>
      <title>Syslog + SSL connection logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-SSL-connection-logs/m-p/445323#M77499</link>
      <description>&lt;P&gt;Hello All,&lt;BR /&gt;
I am trying to configure McAfee ePO to send syslogs to Splunk; ePO requires the use of SSL. I've tried to configure an SSL input on port 6514 for TCP - syslog, and followed all the steps found in the web / manuals / etc. but I can't seem to be able to get this to work.&lt;/P&gt;

&lt;P&gt;Here's my question: Where can I find logs that show the detail of the SSL negotiation with the remote host, and what is failing?&lt;/P&gt;

&lt;P&gt;Thanks all,&lt;/P&gt;

&lt;P&gt;Pablo&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 12:07:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-SSL-connection-logs/m-p/445323#M77499</guid>
      <dc:creator>PabloJulian</dc:creator>
      <dc:date>2019-03-20T12:07:20Z</dc:date>
    </item>
    <item>
      <title>Re: Syslog + SSL connection logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Syslog-SSL-connection-logs/m-p/445324#M77500</link>
      <description>&lt;P&gt;Sending syslog directly to Splunk is against best practice. You should send it to a syslog server like Rsyslog or Syslog-ng. Regardless, you would have to install certificates on the receiving host, otherwise handshake will fail.&lt;/P&gt;

&lt;P&gt;Check out the answer here: &lt;A href="https://answers.splunk.com/answers/658055/setup-secure-encrypted-syslog.html"&gt;https://answers.splunk.com/answers/658055/setup-secure-encrypted-syslog.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;But the splunkd.log would have any errors. /opt/splunk/var/log/splunk |grep -i error&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2019 17:40:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Syslog-SSL-connection-logs/m-p/445324#M77500</guid>
      <dc:creator>bcyates</dc:creator>
      <dc:date>2019-03-20T17:40:40Z</dc:date>
    </item>
  </channel>
</rss>

