Installation

SSL routines:SSL23_GET_CLIENT_HELLO:unknown protocol

AlexK
New Member

Hi all,

We have an excisting index cluster which was installed with version 6.x and gradually upgraded to version 8.1.3.

In the proces of adding two new Heavy forwarders we can not get the HF to properly communicate with the index cluster. The HF are fresh installations using the lates t8.1.3 package.

We get the error as shown in the subject. Since we do not use SSL where a bit lost with regards to this message. 

 

Labels (3)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

Your HF's is probably using e.g. indexer discovery or those are configured by DS. In those cases splunkd are using SSL/TLS even your indexing traffic is plain S2S. You should check that you have same SSL configs on both side HF vs DS vs. CM vs. Indexers. 

There are quite many articles in answer where you could get more hints if needed. Just query from google with

site:community.splunk.com SSL routines:SSL23_GET_CLIENT_HELLO:unknown protocol

and you get those.

r. Ismo 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...