Deployment Architecture

SSL flows within deployed app

pdjhh
Communicator

Hi there.

We have our data ingestion ssl flows distributed to our heavy forwarders within an app. So the certs and outputs.conf are just under app/local and this has worked fine until now. What has happened is we have had a windows HF in the past whereas we've just stood up Linux HFs. The app gets pushed to the new linux HF but the secure connection will not come up.

The errors I'm seeing are these on the indexer side:
ERROR TcpInputProc - Error encountered for connection from src=x.x.x.x:59918. error:140760FC:SSL routines:SSL23_GET_CLIENT_HELLO:unknown protocol

Searching that error points to lots of things such as tls versions, compression on or off etc but as my config is all within the files in the app then this new forwarder has the same config as the old windows one which talks to the indexer succesfully. Just wondering if there's any secret ssl security within that's preventing this working? I've tried regenerating the sslPassword in case it was that but no go.

Thanks.

0 Karma

pdjhh
Communicator

This problem looks to have been caused by pushing hashed passwords in the apps to the new heavy forwarders. This doesn't work with hashed passwords (effecting app deployment) but you need to work around as per the following article:

http://docs.splunk.com/Documentation/Splunk/6.0.1/Security/Deploysecurepasswordsacrossmultipleserver...

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...