Getting Data In

Why SSL status show as "false" despite configuring SSL

VK18
Explorer

Why SSL status show as "false" despite configuring SSL. In Our environment we have enabled TLS configuration between forwarders and receivers. The connection is established and we could see data is coming through secure TLS channel into splunk.

I have validated manually as well using openssl client module and verification was successful with status ok.

We could see for the hosts, SSL as false and it keeps changing at random times to True or False. And connection type is cookedSSL for the False host.

VK18_0-1694514825029.png

 

I have checked all the tcpoutputproc and tcpinputproc in splunkd logs, cannot find any errors related to SSL.

 

But found below WARN messages on one of the forwarders. Is this causing the problem ?

VK18_0-1694515204040.png

Any leads on this.

0 Karma
Get Updates on the Splunk Community!

Learn Splunk Insider Insights, Do More With Gen AI, & Find 20+ New Use Cases You Can ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Buttercup Games: Further Dashboarding Techniques (Part 7)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Stay Connected: Your Guide to April Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...