All Apps and Add-ons

After my logs stopped flowing in from the Microsoft Log Analytics Add-on, I got the following "SSLError"

fredshino
Explorer

The Add-on was working fine, lots of logs flowing in during the past week, but yesterday around 12pm the logs stopped flowing in.

I see some error messages in the internal logs:

"SSLError: EOF occurred in violation of protocol"

Screenshot:
alt text

@jkat54, Any ideas why these errors started all of a sudden?

0 Karma

jkat54
SplunkTrust
SplunkTrust

@fredshino can you come back to this post and provide an update please?

0 Karma

fredshino
Explorer

@jkat54, have you had a chance to look at this?

Thanks in advance!

0 Karma

jkat54
SplunkTrust
SplunkTrust

It looks like the most common cause of this is out of date / less secure versions of openssl.

Which version of splunk are you using?

0 Karma

fredshino
Explorer

7.0.3

Any tips on where to start troubleshooting this? Our Splunk deployment is huge and according to our Splunk team, upgrading to a newer version is not feasible at this moment.

0 Karma

jkat54
SplunkTrust
SplunkTrust

Any chance you have a web proxy or firewall that is malforming the request?

I think that could cause this too,

Troubleshooting this app can be difficult, so hang in there and we’ll get you fixed.

You can google azure log analytics and find curl examples for testing queries, etc.

I’ve seen people use postman app to get auth token and test queries.

0 Karma

jkat54
SplunkTrust
SplunkTrust

Any updates here @fredshino ?

0 Karma
Get Updates on the Splunk Community!

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...