Trying to connect from vendor UF to our indexer through configuring SSL certificate. We have enabled SSL on both sides but still we are struggling with this error "MOST LIKELY CAUSE IS THE SCHEME OR THE PORT NUMBER IS WRONG". I am skeptical trying to figure out what it is and how to troubleshoot this error? And for now, we just disabled the SSL and Splunk are indexing only HTTP data. Does anyone has faced this kind of issue or does anyone have any idea about this!!
The port should default to 9997.
Is there any chance that port is already in use? If so Splunk would use another port.
You could also try manually setting the ports to something that works for you.
This topic offers some guidelines for s configuring your spec file attributes:
http://docs.splunk.com/Documentation/Splunk/Security/ConfigureSplunkforwardingtousesignedcertificate....