All Apps and Add-ons

HEC Token/AWS lambda error

Omarop
Loves-to-Learn Lots

Hello,

I have created a Http Event Collector token for a user. He is using a AWS lambda function in order to access the SPLUNK_HEC_URL and he is receiving the following error:

error0407006A:rsa routines: RSA_padding_check_PKCS1_type_1:invalid padding:../deps/openssl/openssl/cryp
error:04067042:rsa routines: RSA_EAY_PUBLIC_DECRYPT: padding check failed: ../dep/openssl/crypto/rsa/rsa_eay.c: 693:"
error:14000D04B: SSL routines: SSL routines : ssl3_get_key_exchange : bad signature: ../deps/openssl/openssl/ssl/s4_
"_errnoException (util.js : 1022 : 11)"

Has anyone come across this issue before? And if so, can you please assist?

0 Karma

rafael_szt
Explorer

What language is he using? Try disabling SSL certificate validation on the request to Splunk.

0 Karma

Omarop
Loves-to-Learn Lots

He is using json. No I have not, how and where do you disable the SSL certificate?

0 Karma

rafael_szt
Explorer

Hmm, json is not a programming language, rereading your original error I believe it's NodeJS. So he could do the following in his code:

Add

process.env["NODE_TLS_REJECT_UNAUTHORIZED"] = 0;

in code, before calling https.request()

https://stackoverflow.com/questions/10888610/ignore-invalid-self-signed-ssl-certificate-in-node-js-w...

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...