All Apps and Add-ons

If two different versions of Splunk are used, will it affect my service from sending incoming data to each server?

ichesla1111
Path Finder

Splunk versions being used:
Splunk Server 1 = Version 8.2.7
Splunk Server 2 = Version 8.1.1

Background:
I created a service which monitors different folders for incoming data. When a user places new data into one of the folders, Splunk SPL creates a tailored message for the Virtual Machine (VM) to move the data. If message is received by VM, the VM sends the data through a TCP port to another service which verifies the data. If verified, the data will go straight to the Splunk servers via TCP/IP.

Issue
When I updated one of the servers, my whole data transfer process described above stopped working. My services cannot communicate with the VM anymore.

Error Generated in Splunk Logs:
1. "It seems the Splunk default certificates are being used. If certificate validation is turned on using the default certificated (not recommended), results in loss of communication in mixed-version Splunk upgrades."

2.  "Splunk's properly implemented crypto code resulted in the ciphertext being rejected instead of decrypted when AAD validation failed."

Summary of Question:
Since two different versions of Splunk are running, is it affecting the Splunk SPL ability to send a message to the VM/why my VM is not communicating/working anymore?

Thank you.

0 Karma

woodcock
Esteemed Legend

Open a support case.

ichesla1111
Path Finder

Okay, thank you!!!

0 Karma

ichesla1111
Path Finder

Update on Error: My TCP is unable to connect to the other computer

"Error TcpOutFd - Connection to host failed, host refused it.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...