Splunk Search

Curl Command SSL Error on Search Head

harishsplunk7
Explorer

We have a total of five search heads, and while four of them are successfully executing the curl command, one search head is encountering an SSL error, specifically a SSLError with a curl status of 408. 

HTTPSConnectionPool(host='localhost', port=8801): Max retries exceeded with url: /servicesNS/nobody/alert/saved/searches/alert/acl (Caused by SSLError(SSLCertVerificationError(1, '[SSL: CERTIFICATE_VERIFY_FAILED] certificate verify failed: self signed certificate in certificate chain (_ssl.c:1106)')))

what is the  next steps to identify and resolve the root cause of this SSL error. 

0 Karma

richgalloway
SplunkTrust
SplunkTrust

The cause is in the error message: "certificate verify failed: self signed certificate in certificate chain".  Make sure all of the search heads have the same PEM file.

---
If this reply helps you, Karma would be appreciated.
0 Karma

harishsplunk7
Explorer

thank you for the update, all the search head having same pem file. 

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...