Security

Splunk 6 Ciso ips error

fraijof
Explorer

I upgraded Splunk to version 6 and data stopped flowing from our CiscoIPS. My sdee_get.log shows this error:
Wed Oct 16 09:16:53 2013 - ERROR - Connecting to sensor - MY IP: URLError:

I dug in deeper and I think its barking at the negotiation of SSL?
/splunk/lib/python2.7/ssl.py

I changed ssl.py ssl_version=PROTOCOL_SSLv23 to ssl_version=PROTOCOL_TLSv1 and still did not work.
I hope to get this online ASAP.

Tags (1)
0 Karma

dshpritz
SplunkTrust
SplunkTrust

You may want to check out my answer here: http://answers.splunk.com/answers/105193/cisco-ips-error-errno-8/135759. I posted some code that may solve this issue for you.

0 Karma

seanp
Path Finder

I had the same issue doing a new install on Splunk 6. I ended up having to install a Splunk 5.0.5 lightweight forwarder on a separate server and forward it to the central server. When I ran

openssl s_client -connect :443

with the version that is included in Splunk 6 but works fine in version 5.0.5. There seems to be an issue with this on Linux, however I experience the same issue with Windows

http://answers.splunk.com/answers/105193/cisco-ips-error-errno-8

0 Karma

seanp
Path Finder

I tried the very hackish replacing of the OpenSSL binary files in the bin directory with 0.9.8y but only got errors.

0 Karma

jgauthier
Contributor

I was just uncovering this mess. Wouldn't it be possible to include another openssl library somewhere and reference that?

0 Karma

jgauthier
Contributor

Mine is also broken after upgrading. I am still diagnosing this.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Value Insights: Now Generally Available in the CMC

Organizations are under pressure to move faster, control cost, expand AI adoption, and prove value with more ...

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Splunk App Dev Quarterly Roundup: AI, Agents, and Innovation!

Another quarter, another wave of innovation. From complex integrations to pushing the limits ...