Installation

Why is this unknown protocol found in indexer from Windows Universal Forwarder: SSL23_GET_CLIENT_HELLO?

td-security
Observer

I install UF 8.2.4 for Windows and using default pem and CA certificate, I tried to connect UF to the indexer. However, the eventlog information cannot be sent to indexer with the error 

ERROR TcpInputProc - Error encountered for connection from src=192.168.xx.xxx:65251. error:140760FC:SSL routines:SSL23_GET_CLIENT_HELLO:unknown protocol

I search thru the /opt/splunk/var/log/splunk/splunkd.log and not much information can be found. How can I get more detail info to troubleshoot the problem ?

 

Labels (3)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...