All Apps and Add-ons

Getting SSL errors

idsersupport
Explorer

For some reason I am getting the following two errors showing in my syslog data on my esxi hosts:

SSL Handshake failed for stream TCP(local=esxihost:443, peer=splunk:34717), error=SSL Exception: Unexpected EOF
SSLStreamImpl::DoServerHandshake (680fe048) SSL_accept failed with Unexpected EOF

It is the forwarded appliance trying to connect to the the esxi hosts. Any clue how I can fix this?

cpriester
New Member

Just noticed the same issue on our infrastructure. vmware app 2.0 and vcenter UF 5.0.4. Has there been any resolution to this yet? or is the answer upgrade to vmware app 3.0?

0 Karma

idsersupport
Explorer

It is in issue with the vmware splunk app 2.0. I have been in contact with Splunk about this issue. Not have heard back from them.

0 Karma

kml_uvce
Builder

can you give me your inputs and outputs file of sender(forwarder) and inputs file of receiver(indexer) details ...
-Kamal Bisht

0 Karma

sowings
Splunk Employee
Splunk Employee

The local host is 443, so I really hope it's not the forwarder trying to connect. Typically 443 is going to be a (non-default) setting for the Splunk UI.

0 Karma

mjones414
Contributor

I am getting the same thing across all of my ESXi hosts and from vcenter. 2.0.0 vmware app. 5.0.2 indexer, 5.0.2. vcenter UF

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...