Refine your search:

3
1

I have a lot of these ERROR messages in the splunkd.log on my indexing instance, what is it trying to tell me?

A snippet of the log says -

01-22-2010 15:21:24.544 ERROR TcpInputFd - SSL Error = error:1407609C:SSL routines:SSL23_GET_CLIENT_HELLO:http request 
01-22-2010 15:21:24.544 ERROR TcpInputFd - ACCEPT_RESULT=-1 VERIFY_RESULT=0 
01-22-2010 15:21:24.544 ERROR TcpInputFd - SSL Error for fd from HOST:<hostName>, IP:<Ip_Address>, PORT:<port#> 

asked 22 Jan '10, 18:37

Mick's gravatar image

Mick ♦
4.0k1327
accept rate: 52%

edited 04 Jan '11, 19:16

Lowell's gravatar image

Lowell ♦
9.6k635


One Answer:

You will see this error if SSL is enabled on the indexer but not configured to forward w/ssl attempting to make the connections.

To enable SSL forwarding please see this document for details. http://www.splunk.com/base/Documentation/4.0.8/Admin/UseSSLencryptionbetweenforwardersandreceivers

link

answered 22 Jan '10, 19:52

Chris%20R.'s gravatar image

Chris R.
1.0k126
accept rate: 36%

How do I get rid of this error message -- for now at least? (I've filed a bug on this, since ERROR message should only be result of an error condition.)

(22 Jan '10, 20:11) V_at_Splunk

I have no SSL forwarding or receiving setup and I'm still seeing similar error messages.

(13 Apr '10, 22:10) Lowell ♦
Post your answer
toggle preview

Copyright © 2005-2012 Splunk, Inc. All rights reserved.