Security

Why is there certificate exception error while posting data to splunk?

Venkat_Kumar
Loves-to-Learn

Hi Team,

I am getting below error while trying to post data to my splunk using below url. I have installed the certificates in the source system by taking them from browser(lock sysmbol)

Can you please check and help what certificates are exactly installed to post data to below URL

end point url: https://prd-p-jmw56.splunkcloud.com:8088/services/collector/raw

Error Details
java.net.ConnectException: java.security.cert.CertificateException: No name matching prd-p-jmw56.splunkcloud.com found, cause: java.security.cert.CertificateException: No name matching prd-p-jmw56.splunkcloud.com found
 
thanks,
Venkat
Labels (4)
0 Karma

PickleRick
Ultra Champion

Contrary to the certificate served on port 443, the one used on 8088 is a Splunk's internal cert (the cert created  by default on installation).

The one used on the web interface port is a wildcard certificate for the whole splunkcloud .com domain so I presume it's not directly installed on "your" search heads but is served from some HTTP loadbalancer which also works as HTTPS offloading proxy.

I haven't used the cloud yet but I suppose if you want a "proper" trusted certificate you should contact cloud support (you won't be able to upload a certificate and add ssl settings on your own anyway I think).

0 Karma

diogofgm
SplunkTrust
SplunkTrust

Are you sending the data with the HEC token?

Check this docs:
https://docs.splunk.com/Documentation/Splunk/latest/Data/HECExamples

 

------------
Hope I was able to help you. If so, some karma would be appreciated.
0 Karma

Venkat_Kumar
Loves-to-Learn

Hello,

Yes, i am created  HEC token in splunk and using it while trying to send data.

Also, i have modified the end point as below(added "inputs.") as per https://docs.splunk.com/Documentation/Splunk/8.0.3/Data/UsetheHTTPEventCollector# 

end point url: https://inputs.prd-p-jmw56.splunkcloud.com:8088/services/collector/raw 

Based on error, looks like i need to install hostname dedicated certificate. Any idea on how to get it or enable anything in splunk to receive data.

 

Error Details
java.net.ConnectException: java.security.cert.CertificateException: No name matching inputs.prd-p-jmw56.splunkcloud.com found, cause: java.security.cert.CertificateException: No name matching inputs.prd-p-jmw56.splunkcloud.com found

 

0 Karma

diogofgm
SplunkTrust
SplunkTrust

I haven't had much experience with splunk cloud but I recall you can download a UF package that contains all the necessary bit to connect to the cloud instance including the cert chain.

------------
Hope I was able to help you. If so, some karma would be appreciated.
0 Karma

Venkat_Kumar
Loves-to-Learn

@diogofgm Thanks for your response.

Can you please provide me the path where i can check UF package which contains certificate details.

0 Karma

diogofgm
SplunkTrust
SplunkTrust

In Splunk Cloud in the Apps menu you have a Universal forwarder app. In that app you can download the UF package

------------
Hope I was able to help you. If so, some karma would be appreciated.
0 Karma

Venkat_Kumar
Loves-to-Learn

Hi Experts,

Can you please help to guide on below issue

I am getting below error while trying to post data to my splunk using below url. I have installed the certificates in the source system by taking them from browser(lock sysmbol)

Can you please check and help what certificates are exactly installed to post data to below URL

end point url: https://prd-p-jmw56.splunkcloud.com:8088/services/collector/raw

Error Details
java.net.ConnectException: java.security.cert.CertificateException: No name matching prd-p-jmw56.splunkcloud.com found, cause: java.security.cert.CertificateException: No name matching prd-p-jmw56.splunkcloud.com found
 
thanks,
Venkat
0 Karma
Get Updates on the Splunk Community!

Observability Highlights | January 2023 Newsletter

 January 2023New Product Releases Splunk Network Explorer for Infrastructure MonitoringSplunk unveils Network ...

Security Highlights | January 2023 Newsletter

January 2023 Splunk Security Essentials (SSE) 3.7.0 ReleaseThe free Splunk Security Essentials (SSE) 3.7.0 app ...

Platform Highlights | January 2023 Newsletter

 January 2023Peace on Earth and Peace of Mind With Business ResilienceAll organizations can start the new year ...