Getting Data In

Splunk DB Connect: How do I troubleshoot why Java Bridge server not running from these error messages in the jbridge.log?

hoopydave
Path Finder

Running on Windows, DB Connect 1.1.6, Java 1.8.0_31.
Here is the latest in the jbridge.log

2015-03-18 09:37:38,740 INFO Started JavaBridgeServer PID=4748
2015-03-18 09:37:40,269 ERROR Java process returned error code 1! Error: Initializing Splunk context... Environment: SplunkEnvironment{SPLUNK_HOME=D:\Program Files\Splunk,SPLUNK_DB=D:\Program Files\Splunk\var\lib\splunk} Configuring Log4j... Exception in thread "main" com.splunk.config.SplunkConfigurationException: IO Error while reading configuration from Splunkd: javax.net.ssl.SSLHandshakeException: No appropriate protocol (protocol is disabled or cipher suites are inappropriate) at com.splunk.config.rest.RESTAdapter.request(RESTAdapter.java:195) at com.splunk.config.rest.RESTAdapter.readConfig(RESTAdapter.java:203) at com.splunk.config.cache.CachedConfigurationAdapter.readConfig(CachedConfigurationAdapter.java:32) at com.splunk.config.cache.CachedConfigurationAdapter.readStanza(CachedConfigurationAdapter.java:40) at com.splunk.env.SplunkContext.getConfigStanza(SplunkContext.java:313) at com.splunk.env.SplunkContext.initialize(SplunkContext.java:128) at com.splunk.bridge.JavaBridgeServer.main(JavaBridgeServer.java:34) Caused by: javax.net.ssl.SSLHandshakeException: No appropriate protocol (protocol is disabled or cipher suites are inappropriate) at sun.security.ssl.Handshaker.activate(Unknown Source) at sun.security.ssl.SSLSocketImpl.kickstartHandshake(Unknown Source) at sun.security.ssl.SSLSocketImpl.performInitialHandshake(Unknown Source) at sun.security.ssl.SSLSocketImpl.startHandshake(Unknown Source) at sun.security.ssl.SSLSocketImpl.startHandshake(Unknown Source) at sun.net.www.protocol.https.HttpsClient.afterConnect(Unknown Source) at sun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.connect(Unknown Source) at sun.net.www.protocol.https.HttpsURLConnectionImpl.connect(Unknown Source) at com.splunk.rest.Splunkd.request(Splunkd.java:212) at com.splunk.rest.Splunkd.request(Splunkd.java:98) at com.splunk.config.rest.RESTAdapter.request(RESTAdapter.java:193) ... 6 more
2015-03-18 09:37:40,269 ERROR Command output: None
2015-03-18 09:37:43,108 INFO Checking for obsolete java libraries in D:\Program Files\Splunk\etc\apps\dbx\bin\lib

0 Karma
1 Solution

hoopydave
Path Finder

So what I needed to do is re-enable SSLv3 in the java.security file in the Java directory. Mine was in \[SERVER_NAME]\c$\Program Files\Java\jre1.8.0_31\lib\security. Remove SSLv3 from the last line:
jdk.tls.disabledAlgorithms=SSLv3

I saved the file and it worked. Javabridge is now running.

View solution in original post

jdbtee
Path Finder

You may also need to run notepad as Admin to change the setting in java.security, as it states another process is using the file, which is explorer.exe.

0 Karma

hoopydave
Path Finder

So what I needed to do is re-enable SSLv3 in the java.security file in the Java directory. Mine was in \[SERVER_NAME]\c$\Program Files\Java\jre1.8.0_31\lib\security. Remove SSLv3 from the last line:
jdk.tls.disabledAlgorithms=SSLv3

I saved the file and it worked. Javabridge is now running.

aphilip
New Member

Ran into jbridge not running issue on Linux when switched to jre1.8 and this fix worked. Thanks!

0 Karma

MuS
SplunkTrust
SplunkTrust

Thanks for this! Had to make DBX 1.1.7 work with Splunk 7.0.1 and this was the last missing setting - thanks 🙂

BTW: another example that a lot of problems you encounter using Splunk, are actually not related to Splunk at all 😉

0 Karma

andrey2007
Contributor

Try to turn off SSLv3

0 Karma

hoopydave
Path Finder

I'm sorry, but I don't understand how to turn off SSLv3. Is that within Splunk? Java? Would that have changed sometime between Java 8 u25 and u31? As I mentioned before Splunk ran fine on Java 8 u25. Thanks!

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...