All Apps and Add-ons

Why am I getting the following error when trying to integrate Splunk with Proofpoint?: "Invalid key in stanza [SSL] in /opt/splunkforwarder/etc/system/local/inputs.conf, line 8: serverCERT"

titoluna07
Explorer

I am getting the following error: Invalid key in stanza [SSL] in /opt/splunkforwarder/etc/system/local/inputs.conf, line 8: serverCERT (value: /opt/splunkforwarder/etc/certs/proofpoint_certs/proofpoint-ServerCertificate.crt).

Can anyone help me? I am trying to integrate Splunk with Proofpoint and that is the certificate Proofpoint gives me.

0 Karma
1 Solution

gjanders
SplunkTrust
SplunkTrust

As per inputs.conf there is no serverCERT, perhaps you mean (from the docs):

[SSL]
* Set the following specifications for receiving Secure Sockets Layer (SSL)
  communication underneath this stanza name.

serverCert = <path>
* The full path to the server certificate Privacy-Enhanced Mail (PEM)
  format file.
* PEM is the most common text-based storage format for SSL certificate files.
* No default.

Where the capitalisation is case sensitive.

View solution in original post

0 Karma

gjanders
SplunkTrust
SplunkTrust

As per inputs.conf there is no serverCERT, perhaps you mean (from the docs):

[SSL]
* Set the following specifications for receiving Secure Sockets Layer (SSL)
  communication underneath this stanza name.

serverCert = <path>
* The full path to the server certificate Privacy-Enhanced Mail (PEM)
  format file.
* PEM is the most common text-based storage format for SSL certificate files.
* No default.

Where the capitalisation is case sensitive.

0 Karma

titoluna07
Explorer

Thanks!
That solved the error I was getting.
But I am still having problem while testing Proofpoint connectivity with splunk, I am getting this ssl=false
is that normal? anyone can help me?
11-02-2018 09:59:04.690 -0400 INFO StatusMgr - destPort=6514, eventType=connect_done, group=tcpin_connections, sourceHost=, sourceIp=, sourcePort=49146, statusee=TcpInputProcessor
11-02-2018 09:59:04.690 -0400 INFO StatusMgr - group=tcpin_connections, sourcePort=6514, ssl=false, statusee=TcpInputProcessor

Thanks!

0 Karma

gjanders
SplunkTrust
SplunkTrust

This might be worth asking a new question but first have a read of About securing data from forwarders that should advise about the inputs.conf settings you would normally use to use an SSL certificate which might help if you want to have an SSL listener port in the inputs.conf file...

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...