All Apps and Add-ons

Why am I getting the following error when trying to integrate Splunk with Proofpoint?: "Invalid key in stanza [SSL] in /opt/splunkforwarder/etc/system/local/inputs.conf, line 8: serverCERT"

titoluna07
Explorer

I am getting the following error: Invalid key in stanza [SSL] in /opt/splunkforwarder/etc/system/local/inputs.conf, line 8: serverCERT (value: /opt/splunkforwarder/etc/certs/proofpoint_certs/proofpoint-ServerCertificate.crt).

Can anyone help me? I am trying to integrate Splunk with Proofpoint and that is the certificate Proofpoint gives me.

0 Karma
1 Solution

gjanders
SplunkTrust
SplunkTrust

As per inputs.conf there is no serverCERT, perhaps you mean (from the docs):

[SSL]
* Set the following specifications for receiving Secure Sockets Layer (SSL)
  communication underneath this stanza name.

serverCert = <path>
* The full path to the server certificate Privacy-Enhanced Mail (PEM)
  format file.
* PEM is the most common text-based storage format for SSL certificate files.
* No default.

Where the capitalisation is case sensitive.

View solution in original post

0 Karma

gjanders
SplunkTrust
SplunkTrust

As per inputs.conf there is no serverCERT, perhaps you mean (from the docs):

[SSL]
* Set the following specifications for receiving Secure Sockets Layer (SSL)
  communication underneath this stanza name.

serverCert = <path>
* The full path to the server certificate Privacy-Enhanced Mail (PEM)
  format file.
* PEM is the most common text-based storage format for SSL certificate files.
* No default.

Where the capitalisation is case sensitive.

0 Karma

titoluna07
Explorer

Thanks!
That solved the error I was getting.
But I am still having problem while testing Proofpoint connectivity with splunk, I am getting this ssl=false
is that normal? anyone can help me?
11-02-2018 09:59:04.690 -0400 INFO StatusMgr - destPort=6514, eventType=connect_done, group=tcpin_connections, sourceHost=, sourceIp=, sourcePort=49146, statusee=TcpInputProcessor
11-02-2018 09:59:04.690 -0400 INFO StatusMgr - group=tcpin_connections, sourcePort=6514, ssl=false, statusee=TcpInputProcessor

Thanks!

0 Karma

gjanders
SplunkTrust
SplunkTrust

This might be worth asking a new question but first have a read of About securing data from forwarders that should advise about the inputs.conf settings you would normally use to use an SSL certificate which might help if you want to have an SSL listener port in the inputs.conf file...

0 Karma
Get Updates on the Splunk Community!

Improve Your Security Posture

Watch NowImprove Your Security PostureCustomers are at the center of everything we do at Splunk and security ...

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...