Security

HTTP Event Collector SSL problem

DMohn
Motivator

Hi all,

I am trying to send events to HEC locally via CLI and keep getting a SSL error. I have looked up several docs, but I have not yet found the solution to it. My problem is like this:

Command:
curl -vvv -k -H "Authorization: Splunk my-hec-token" https://mysplunkhost:8088/services/collector/event -d '{ [aWholeLotOfJSONformattedData] }'

Return is:

* Hostname was NOT found in DNS cache
*   Trying xx.xx.xx.xx...
* Connected to mysplunkhost (xx.xx.xx.xx) port 8088 (#0)
* successfully set certificate verify locations:
*   CAfile: none
  CApath: /etc/ssl/certs/
* SSLv3, TLS unknown, Certificate Status (22):
* SSLv3, TLS handshake, Client hello (1):
* error:140770FC:SSL routines:SSL23_GET_SERVER_HELLO:unknown protocol
* Closing connection 0
curl: (35) error:140770FC:SSL routines:SSL23_GET_SERVER_HELLO:unknown protocol

Any advise on where I can fix this?

0 Karma
1 Solution

DMohn
Motivator

Found the solution by myself, after a while.

If you don't enable SSL in the http input setting, Splunk won't accept https calls 🙂

So be aware of that!

View solution in original post

0 Karma

DMohn
Motivator

Found the solution by myself, after a while.

If you don't enable SSL in the http input setting, Splunk won't accept https calls 🙂

So be aware of that!

0 Karma
Get Updates on the Splunk Community!

Changes to Splunk Instructor-Led Training Completion Criteria

We’re excited to share an update to our instructor-led training program that enhances the learning experience ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

❄️ Welcome the new year with our January lineup of Community Office Hours, Tech Talks, and Webinars! 🎉 ...

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...