Getting Data In

curl (35) Unknown SSL protocol error in connection to .splunkcloud.com:8089

bschaap
Path Finder

I'm following the REST API tutorial with Splunk Cloud but receiving the error below. Url, ip address, username, and password are sanitized.

curl -v -k -u : https://deployment-name.splunkcloud.com:8089/servicesNS//search/saved/searches/ -d name=mysearch -d search=*

* Hostname was NOT found in DNS cache

* Trying ##.###.###.###...

* Connected to deployment-name.splunkcloud.com (##.###.###.###) port 8089 (#0)

* successfully set certificate verify locations:

* CAfile: none

CApath: /etc/ssl/certs

* SSLv3, TLS handshake, Client hello (1):

* Unknown SSL protocol error in connection to deployment-name.splunkcloud.com:8089

* Closing connection 0

curl: (35) Unknown SSL protocol error in connection to deployment-name.splunkcloud.com:8089

Tags (2)
0 Karma
1 Solution

bschaap
Path Finder

This turned out to be a firewall issue even though it did not appear to be initially. See comments for more details.

View solution in original post

0 Karma

Sobhiapetter
New Member

Like you I am using ERR SSL PROTOCOL ERROR Not Responding site to get that error solution, and believe me I found the perfect solutions from that site and there is the number of problems described and their solution in the perfect manner.

0 Karma

bschaap
Path Finder

This turned out to be a firewall issue even though it did not appear to be initially. See comments for more details.

0 Karma

gjanders
SplunkTrust
SplunkTrust

You are already using the insecure switch, can you confirm that curl has the available SSL libraries? Such as running against https://google.com ?

Also double check the curl --version ...

0 Karma

bschaap
Path Finder

It turns out that this was a firewall issue. It didn't appear to be initially because the behavior was different when trying an invalid port instead of 8089. Using an invalid port would wait for a timeout. Port 8089 didn't timeout and instead returned the error message immediately. Once the firewall was modified to allow port 8089 outbound then it began working.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...