All Apps and Add-ons

TA for Microsoft Cloud Services - ERROR TcpInputProc - Message rejected

vpsmax
Path Finder

Hello.

Currently, we are looking to resolve an issue using the TA for Microsoft Cloud Services.  The TA has been installed on our Heavy Forwarder and used to ingest IIS log files from a Storage Blob.  Below are the error messages we receive ...

ERROR TcpInputProc - Message rejected. Received unexpected message of size=369295616 bytes from src=xxx.xxx.xxx.xxx:65138 in streaming mode. Meximum message size allowed=67108864. Possible invalid source sending data to splunktcp port or valid source sending unsupported payload.

ERROR ApplicationUpdater - Error checking for update, URL=https://apps.splunk.com/api/apps:resolve/checkforupgrade: error:14090086:SSL routines:ssl3_get_server_certificate:certificate verify failed - please check the output of the 'openssl verify' command for the certificates involved; note that if certificate verification is enabled (requireClientCert or sslVerifyServerCert set to "true"), the CA certificate and the server certificate should not have the same Common Name.

ERROR X509Verify - X509 certificate (CN=GlobalSign,O=GlobalSign Root CA - R3) failed validation; error=19, reason="self signed certificate in certificate chain"

We have checked the SSL configurations ...

server.conf

[sslConfig]
sslRootCAPath = /opt/splunk/etc/auth/cacert.pem

inputs.conf

[splunktcp-ssl:9997]
disabled = 0

[SSL]
serverCert = $SPLUNK_HOME/etc/auth/server.pem
sslPassword = password
requireClientCert = false

And they look fine.  Has anyone else faced something similar?  If so, what did you to resolve this issue.  Thanks.

Regards,
Max

 

Labels (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...