Getting Data In
Highlighted

How to fix "ERROR TcpInputConfig - SSL context not found" when using inputs.conf [tcp-ssl://6514]?

Contributor

Getting error: "TcpInputConfig - SSL context not found" when inputs.conf in etc/system/local has:

[tcp-ssl://6514]
connection_host = dns
sourcetype = syslog
disabled=0

What must be done to fix this error?

Highlighted

Re: How to fix "ERROR TcpInputConfig - SSL context not found" when using inputs.conf [tcp-ssl://6514]?

Contributor

Needed to add the SSL stanza to inputs.conf. Now sending syslog data to splunk over TLS/SSL.

[tcp-ssl://6514]
connection_host = dns
sourcetype = syslog
disabled = 0

[SSL]
rootCA = $SPLUNKHOME/etc/auth/cacert.pem
serverCert = $SPLUNK
HOME/etc/auth/server.pem
password = $1$B3HE+YB7UQbp

0 Karma
Highlighted

Re: How to fix "ERROR TcpInputConfig - SSL context not found" when using inputs.conf [tcp-ssl://6514]?

Contributor

This blog was helpful in figuring out how to use Splunk certs for syslog over TCP-SSL.

https://wiki.splunk.com/Community:Splunk2Splunk_SSL_DefaultCerts

0 Karma
Highlighted

Re: How to fix "ERROR TcpInputConfig - SSL context not found" when using inputs.conf [tcp-ssl://6514]?

Path Finder
0 Karma