All Apps and Add-ons

If two different versions of Splunk are used, will it affect my service from sending incoming data to each server?

ichesla1111
Path Finder

Splunk versions being used:
Splunk Server 1 = Version 8.2.7
Splunk Server 2 = Version 8.1.1

Background:
I created a service which monitors different folders for incoming data. When a user places new data into one of the folders, Splunk SPL creates a tailored message for the Virtual Machine (VM) to move the data. If message is received by VM, the VM sends the data through a TCP port to another service which verifies the data. If verified, the data will go straight to the Splunk servers via TCP/IP.

Issue
When I updated one of the servers, my whole data transfer process described above stopped working. My services cannot communicate with the VM anymore.

Error Generated in Splunk Logs:
1. "It seems the Splunk default certificates are being used. If certificate validation is turned on using the default certificated (not recommended), results in loss of communication in mixed-version Splunk upgrades."

2.  "Splunk's properly implemented crypto code resulted in the ciphertext being rejected instead of decrypted when AAD validation failed."

Summary of Question:
Since two different versions of Splunk are running, is it affecting the Splunk SPL ability to send a message to the VM/why my VM is not communicating/working anymore?

Thank you.

0 Karma

woodcock
Esteemed Legend

Open a support case.

ichesla1111
Path Finder

Okay, thank you!!!

0 Karma

ichesla1111
Path Finder

Update on Error: My TCP is unable to connect to the other computer

"Error TcpOutFd - Connection to host failed, host refused it.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...