Hi,
I have upgraded my SPLUNK from version 6.6.1 to 7.0.0. After upgrade I am seeing some ssl exceptions and indexer is not taking data. I am using 6.3.3 version for Splunk forwarder.
**Errors in splunkd.log**
10-09-2017 16:39:22.628 +0200 WARN SSLCommon - Received fatal SSL3 alert. ssl_state='SSLv3 read client hello C', alert_description='protocol version'.
10-09-2017 16:39:22.628 +0200 WARN HttpListener - Socket error from 127.0.0.1 while idling: error:1408A10B:SSL routines:ssl3_get_client_hello:wrong version numbe
There are some known issues and workaround for it. even though these workaround is for older version, I have tried but still getting same errors.
http://docs.splunk.com/Documentation/Splunk/6.6.0/ReleaseNotes/KnownIssues#Upgrade_Issues
Not sure if indexer is not taking data because of these errors.
does anyone have encounter such problem or have idea how to fix it ?
Thanks
Ankit
↧