HI,
I had the same issue.
The splunk server log showed some SSL3 issues.
"routines:SSL3_GET_RECORD:wrong version number" as this was a brand new installation of the forwarder, I had to search Mr.Google for quite a while to find the right answer.
The only kind of workaround I could find was to enable the insecure SSL-Version.
https://answers.splunk.com/answers/552516/ssl-error-after-upgrading-from-661-to-662.html
... View more