Security

invalid key in ssl stanza

cmahan
Path Finder

Any ideas why I am getting these errors? It seems like the forwarder connects ok and is working as ssl... but i see these errors at startup

Checking prerequisites...
Checking mgmt port [8089]: open
Checking conf files for problems...
Invalid key in stanza [SSL] in C:\Program Files\SplunkUniversalF
orwarder\etc\apps\1BoxAMI_WinEvt_Perf\local\inputs.conf, line 5: sslRootCAPath
(value: $SPLUNK_HOME/etc/apps/1BoxAMI_WinEvt_Perf/certs/cacert.pem)
Invalid key in stanza [SSL] in C:\Program Files\SplunkUniversalF
orwarder\etc\apps\1BoxAMI_WinEvt_Perf\local\inputs.conf, line 6: sslCertPath (v
alue: $SPLUNK_HOME/etc/apps/1BoxAMI_WinEvt_Perf/certs/server.pem)
Invalid key in stanza [SSL] in C:\Program Files\SplunkUniversalF
orwarder\etc\apps\1BoxAMI_WinEvt_Perf\local\inputs.conf, line 8: compressed (va
lue: true)
Invalid key in stanza [SSL] in C:\Program Files\SplunkUniversalF
orwarder\etc\apps\1BoxAMI_WinEvt_Perf\local\inputs.conf, line 9: useClientSSLCom
pression (value: true)
Invalid key in stanza [WMI:Service] in C:\Program Files\SplunkUn
iversalForwarder\etc\apps\1BoxAMI_WinEvt_Perf\local\inputs.conf, line 106: wql
(value: SELECT Name, Caption, State, Status, StartMode, StartName, PathName, De
scription FROM Win32_Service)
Your indexes and inputs configurations are not internally consis
tent. For more information, run 'splunk btool check --debug'
Done
All preliminary checks passed.

Tags (3)
0 Karma

cmahan
Path Finder

I think i figured it out... Those stanzas don't go in the Input of the forwarder, they go in the input of the indexer.

0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...