Getting Data In

Problem with Proofpoint Integration, anyone can help me?

titoluna07
Explorer

I am having a problem while testing Proofpoint connectivity with splunk, I am getting this ssl=falseon the metrics.log
is that normal?
anyone can help me?

11-02-2018 09:59:04.690 -0400 INFO  StatusMgr - destPort=6514, eventType=connect_done, group=tcpin_connections, sourceHost=, sourceIp=, sourcePort=49146, statusee=TcpInputProcessor
11-02-2018 09:59:04.690 -0400 INFO  StatusMgr - group=tcpin_connections, sourcePort=6514, ssl=false, statusee=TcpInputProcessor

This is the rest of the log:

1-02-2018 09:59:04.693 -0400 INFO  StatusMgr - destPort=6514, eventType=connect_close, group=tcpin_connections, sourceHost=, sourceIp=, sourcePort=49146, statusee=TcpInputProcessor
11-02-2018 09:59:04.857 -0400 INFO  StatusMgr - destPort=6514, eventType=connect_done, group=tcpin_connections, sourceHost=, sourceIp=, sourcePort=49148, statusee=TcpInputProcessor
11-02-2018 09:59:04.857 -0400 INFO  StatusMgr - group=tcpin_connections, sourcePort=6514, ssl=false, statusee=TcpInputProcessor
11-02-2018 09:59:07.887 -0400 INFO  Metrics - group=per_source_thruput, series="tcp:6514", kbps=0.024603096025277185, eps=0.06451618522377423, kb=0.7626953125, ev=2, avg_age=0, max_age=0
11-02-2018 09:59:07.887 -0400 INFO  Metrics - group=tcpin_connections, :49146:6514, connectionType=raw, sourcePort=49146, sourceHost=, sourceIp=, destPort=6514, kb=0.00, _tcp_Bps=0.00, _tcp_KBps=0.00, _tcp_avg_thruput=0.00, _tcp_Kprocessed=0.00, _tcp_eps=0.00, _process_time_ms=0, evt_misc_kBps=0.00, evt_raw_kBps=0.00, evt_fields_kBps=0.00, evt_fn_kBps=0.00, evt_fv_kBps=0.00, evt_fn_str_kBps=0.00, evt_fn_meta_dyn_kBps=0.00, evt_fn_meta_predef_kBps=0.00, evt_fn_meta_str_kBps=0.00, evt_fv_num_kBps=0.00, evt_fv_str_kBps=0.00, evt_fv_predef_kBps=0.00, evt_fv_offlen_kBps=0.00, evt_fv_fp_kBps=0.00
11-02-2018 09:59:07.887 -0400 INFO  Metrics - group=tcpin_connections, :49148:6514, connectionType=raw, sourcePort=49148, sourceHost=, sourceIp=, destPort=6514, kb=0.30, _tcp_Bps=101.33, _tcp_KBps=0.10, _tcp_avg_thruput=0.10, _tcp_Kprocessed=0.30, _tcp_eps=0.00, _process_time_ms=0, evt_misc_kBps=0.00, evt_raw_kBps=0.00, evt_fields_kBps=0.00, evt_fn_kBps=0.00, evt_fv_kBps=0.00, evt_fn_str_kBps=0.00, evt_fn_meta_dyn_kBps=0.00, evt_fn_meta_predef_kBps=0.00, evt_fn_meta_str_kBps=0.00, evt_fv_num_kBps=0.00, evt_fv_str_kBps=0.00, evt_fv_predef_kBps=0.00, evt_fv_offlen_kBps=0.00, evt_fv_fp_kBps=0.00
11-02-2018 09:59:09.706 -0400 INFO  StatusMgr - destPort=6514, eventType=connect_close, group=tcpin_connections, sourceHost=, sourceIp=, sourcePort=49148, statusee=TcpInputProcessor
11-02-2018 09:59:38.888 -0400 INFO  Metrics - group=tcpin_connections, :49148:6514, connectionType=raw, sourcePort=49148, sourceHost=, sourceIp=, destPort=6514, kb=0.00, _tcp_Bps=0.00, _tcp_KBps=0.00, _tcp_avg_thruput=0.01, _tcp_Kprocessed=0.30, _tcp_eps=0.00, _process_time_ms=0, evt_misc_kBps=0.00, evt_raw_kBps=0.00, evt_fields_kBps=0.00, evt_fn_kBps=0.00, evt_fv_kBps=0.00, evt_fn_str_kBps=0.00, evt_fn_meta_dyn_kBps=0.00, evt_fn_meta_predef_kBps=0.00, evt_fn_meta_str_kBps=0.00, evt_fv_num_kBps=0.00, evt_fv_str_kBps=0.00, evt_fv_predef_kBps=0.00, evt_fv_offlen_kBps=0.00, evt_fv_fp_kBps=0.00

I don't know how to see any other errors, everything seems ok,
On Proofpoint portal, about the connectivity test using port 6514 page says:
OK: tcp
FAIL: tls

Thanks!

Tags (1)
0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...