Getting Data In

Why am I getting error "SSL certificate generation failed" while starting the splunkd process on the universal forwarder?

kpavan
Path Finder

Hi All,

I'm unable to start the splunkd process on the universal forwarder and it's giving an error that SSL certificate generation failed. Could you please let me know if there any specific configuration issue?

Thanks!
Pavan

0 Karma

splunkadunk5
Explorer

In my case it ended up being Cylance.

gesman_splunk
Splunk Employee
Splunk Employee

We had reports that antivirus services might cause that.

Check if there are any antivirus or similar resource-hungry services are running and try disabling them and restarting Splunk to test.

Also lack of resources - particularly memory could be generally related cause.

0 Karma

shirishkamat84
Path Finder

Did anyone figured this out and identified a fix. I did not find any answers to this particular problem

0 Karma

jwelch_splunk
Splunk Employee
Splunk Employee

If you are running AV try disabling it and see if that fixes it

0 Karma

jkuma39
New Member

In My case, i tried installing a new splunkforwader and started splunk and got below error. Can you please let me know what can be reason for this?

Splunk> CSI: Logfiles.

Checking prerequisites...
Checking mgmt port [8089]: open
ERROR: pid 13672 terminated with signal 11
SSL certificate generation failed.

Iinux Version: Linux lgdwd511 2.6.32-696.6.3.el6.x86_64 #1 SMP Fri Jun 30 13:24:18 EDT 2017 x86_64 x86_64 x86_64 GNU/Linux

0 Karma

jmallorquin
Builder

Hi,

Did you change the default certificate?
Did you review the splunkd.log file?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...