Splunk Enterprise

How to troubleshoot error with SH and index cluster?

SplunkNinja
Path Finder

I have a SH that is not part of SH Cluster.  The SH is connected to an Index Cluster.  I am seeing the following errors on the Indexers (W.X.Y.Z is the IP address of the SH)

ERROR TcpInputProc [2317 FwdDataReceiverThread] - Error encountered for connection from src=W.X.Y.Z:46788. error:140760FC:SSLroutines:SSL23_GET_CLIENT_HELLO:unknown protocol

I don't think there is a mismatch of sslVersions.   Please help me troubleshoot this.

 

Labels (3)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

It looks like the SH is trying to send its logs to the indexers, but doesn't have the correct SSL config.  Verify the SH has the same outputs.conf settings as the SHC.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

It looks like the SH is trying to send its logs to the indexers, but doesn't have the correct SSL config.  Verify the SH has the same outputs.conf settings as the SHC.

---
If this reply helps you, Karma would be appreciated.

SplunkNinja
Path Finder

Thanks @richgalloway 

Yes - the outputs.conf on the SH did not have a reference to the SSL/TLS cert being used.  I added the path to the cert file and password.  it's now working 😀

Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Beyond Detection: How Splunk and Cisco Integrated Security Platforms Transform ...

Financial services organizations face an impossible equation: maintain 99.9% uptime for mission-critical ...

Customer success is front and center at .conf25

Hi Splunkers, If you are not able to be at .conf25 in person, you can still learn about all the latest news ...

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...