Splunk Search

Curl Command SSL Error on Search Head

harishsplunk7
Explorer

We have a total of five search heads, and while four of them are successfully executing the curl command, one search head is encountering an SSL error, specifically a SSLError with a curl status of 408. 

HTTPSConnectionPool(host='localhost', port=8801): Max retries exceeded with url: /servicesNS/nobody/alert/saved/searches/alert/acl (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self signed certificate in certificate chain (_ssl.c:1106)')))

what is the  next steps to identify and resolve the root cause of this SSL error. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The cause is in the error message: "certificate verify failed: self signed certificate in certificate chain".  Make sure all of the search heads have the same PEM file.

---
If this reply helps you, Karma would be appreciated.
0 Karma

harishsplunk7
Explorer

thank you for the update, all the search head having same pem file. 

0 Karma
Get Updates on the Splunk Community!

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...