Getting Data In

SSL Error in Splunk indexer

RAYUDU_NARA
Explorer

Hi,

Recently we upgraded Splunk indexer from the version 6.5.2 to 6.6.3. Now we have many SSL errors are there in logs. what are these errors ? Because of these error's any impact on Splunk performance ?

09-12-2017 02:07:33.824 +0100 WARN SSLCommon - Received fatal SSL3 alert. ssl_state='SSLv3 read client hello C', alert_description='handshake failure'.
09-12-2017 02:07:33.824 +0100 WARN HttpListener - Socket error from "IP Address" while idling: error:1408A0C1:SSL routines:ssl3_get_client_hello:no shared cipher

0 Karma

yannK
Splunk Employee
Splunk Employee

The cyphers changed on splunk 6.6.0, the clarifications are here :
see http://docs.splunk.com/Documentation/Splunk/6.6.3/ReleaseNotes/Knownissues

Options :

  • Upgrade the forwarders to 6.6.* and check again.
  • or change the cypher conditions on the indexer, see link above.
0 Karma
Take the 2021 Splunk Career Survey

Help us learn about how Splunk has
impacted your career by taking the 2021 Splunk Career Survey.

Earn $50 in Amazon cash!