<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UF communication over the deployment server. in Installation</title>
    <link>https://community.splunk.com/t5/Installation/UF-communication-over-the-deployment-server/m-p/669741#M13427</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254391"&gt;@MayurMangoli&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;let me know if I can help you more, or, please, accept one answer for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 26 Nov 2023 15:07:25 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-11-26T15:07:25Z</dc:date>
    <item>
      <title>UF communication over the deployment server.</title>
      <link>https://community.splunk.com/t5/Installation/UF-communication-over-the-deployment-server/m-p/669282#M13406</link>
      <description>&lt;P&gt;&lt;STRONG&gt;i have installed the deployment server where configured required inputs.conf&amp;nbsp;and outputs.conf for ingesting logs from UF to my indexer&amp;nbsp; on the deployment-app of deployment server, and configured the UF forwarder to the deployment server, i found the new host details in the deployment server under the forward management tab. And pointed to appropriate classes and apps from the forward-management&amp;nbsp; configuration. Still I'm not able to get the logs on the indexer.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;when i see the error on the Splunkd log of uf.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Find the below error&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;11-20-2023 17:25:40.602 +0400 ERROR X509Verify - X509 certificate (O=SplunkUser,CN=SplunkServerDefaultCert) failed validation; error=7, reason="certificate signature failure"&lt;BR /&gt;11-20-2023 17:25:40.602 +0400 WARN SSLCommon - Received fatal SSL3 alert. ssl_state='SSLv3 read server certificate B', alert_description='decrypt error'.&lt;BR /&gt;11-20-2023 17:25:40.602 +0400 WARN HttpPubSubConnection - Unable to parse message from PubSubSvr:&lt;BR /&gt;11-20-2023 17:25:40.602 +0400 INFO HttpPubSubConnection - Could not obtain connection, will retry after=86.429 seconds.&lt;BR /&gt;11-20-2023 17:25:40.778 +0400 INFO WatchedFile - Will begin reading at offset=2295058 for file='/var/log/audit/audit.log'.&lt;BR /&gt;11-20-2023 17:25:46.129 +0400 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/var/log/anaconda/ks-script-lk6ot_yw.log'.&lt;BR /&gt;11-20-2023 17:25:46.130 +0400 INFO WatchedFile - File too small to check seekcrc, probably truncated. Will re-read entire file='/var/log/anaconda/ks-script-wo9l091q.log'.&lt;BR /&gt;11-20-2023 17:25:49.856 +0400 INFO DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;BR /&gt;11-20-2023 17:26:01.857 +0400 INFO DC:DeploymentClient - channel=tenantService/handshake Will retry sending handshake message to DS; err=not_connected&lt;BR /&gt;11-20-2023 17:26:07.910 +0400 INFO ScheduledViewsReaper - Scheduled views reaper run complete. Reaped count=0 scheduled views&lt;BR /&gt;11-20-2023 17:26:07.914 +0400 INFO TcpOutputProc - Removing quarantine from idx=192.168.1.5:9997&lt;BR /&gt;11-20-2023 17:26:07.914 +0400 INFO TcpOutputProc - Removing quarantine from idx=192.168.1.6:9997&lt;BR /&gt;11-20-2023 17:26:07.921 +0400 ERROR TcpOutputFd - Read error. Connection reset by peer&lt;BR /&gt;11-20-2023 17:26:07.928 +0400 ERROR TcpOutputFd - Read error. Connection reset by peer&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 04:22:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/UF-communication-over-the-deployment-server/m-p/669282#M13406</guid>
      <dc:creator>MayurMangoli</dc:creator>
      <dc:date>2023-11-21T04:22:38Z</dc:date>
    </item>
    <item>
      <title>Re: UF communication over the deployment server.</title>
      <link>https://community.splunk.com/t5/Installation/UF-communication-over-the-deployment-server/m-p/669298#M13407</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254391"&gt;@MayurMangoli&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;did you configured your Indexers to receive encrypted logs?&lt;/P&gt;&lt;P&gt;It seems that you forgot to add the correct configuration in the outputs.conf that you deployed to your UFs.&lt;/P&gt;&lt;P&gt;For more infos see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.12/Security/Aboutsecuringdatafromforwarders" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.12/Security/Aboutsecuringdatafromforwarders&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 07:40:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/UF-communication-over-the-deployment-server/m-p/669298#M13407</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-21T07:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: UF communication over the deployment server.</title>
      <link>https://community.splunk.com/t5/Installation/UF-communication-over-the-deployment-server/m-p/669738#M13424</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;i just checked the configuration, and seems after changing the syanza, it worked and started connecting.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2023 14:28:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/UF-communication-over-the-deployment-server/m-p/669738#M13424</guid>
      <dc:creator>MayurMangoli</dc:creator>
      <dc:date>2023-11-26T14:28:53Z</dc:date>
    </item>
    <item>
      <title>Re: UF communication over the deployment server.</title>
      <link>https://community.splunk.com/t5/Installation/UF-communication-over-the-deployment-server/m-p/669741#M13427</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/254391"&gt;@MayurMangoli&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;let me know if I can help you more, or, please, accept one answer for the other people of Community.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2023 15:07:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/UF-communication-over-the-deployment-server/m-p/669741#M13427</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-26T15:07:25Z</dc:date>
    </item>
  </channel>
</rss>

