All Apps and Add-ons

Why am I getting "An unexpected TLS packet was received" trying to install Splunk for Palo Alto Networks in Splunk Light 6.3.2 on Ubuntu 14.04.3 LTS?

New Member


I'm trying to install the Splunk for Palo Alto Networks Addin/App for Splunk onto an instance of Splunk Light running on top of Ubuntu 14.04.3 LTS. The installation instructions indicate the package may be downloaded directly (which I have done) or installed from git.

I have attempted the git method, but I am getting an error as below:

fatal: unable to access '': gnutls_handshake() failed: An unexpected TLS packet was received.

I'm not sure how to handle the direct download installation method. There doesn't appear to be instructions for this. I downloaded the .tgz and extracted to the /opt/splunk/etc/apps directory and restarted Splunk, but I don't see anything. Note that I am using Splunk Light and not Splunk Enterprise - I don't think the light version supports downloading apps from the apps homepage as is described in the documentation.

By the way, I am pretty inexperienced with Splunk so I apologize in advance if I omitted anything here.

Any help would be appreciated. Thank you.

0 Karma

Splunk Employee
Splunk Employee

In general, packaged apps are not supported inside of Splunk Light - I think that this includes 3rd party apps that are prebuilt.

Also the error you're seeing is likely to do with git, not anything Splunk related. You might be able to use apt-get to install a version of git that supports openssl instead of gnutls, but that's an Ubuntu / git thing, not a Splunk thing.

0 Karma


Hi mjung,

The Palo Alto Networks App for Splunk is an App for Splunk Enterprise, not Splunk Light. Compatibility is indicated on the app's homepage:

0 Karma

New Member

Sorry I forgot to say Splunk is running as Splunk Light Version 6.3.2. We do have a license - it is not the free version.

0 Karma
Get Updates on the Splunk Community!

Optimize Cloud Monitoring

  TECH TALKS Optimize Cloud Monitoring Tuesday, August 13, 2024  |  11:00AM–12:00PM PST   Register to ...

What's New in Splunk Cloud Platform 9.2.2403?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.2.2403! Analysts can ...

Stay Connected: Your Guide to July and August Tech Talks, Office Hours, and Webinars!

Dive into our sizzling summer lineup for July and August Community Office Hours and Tech Talks. Scroll down to ...