Security

Splunk 6 Ciso ips error

fraijof
Explorer

I upgraded Splunk to version 6 and data stopped flowing from our CiscoIPS. My sdee_get.log shows this error:
Wed Oct 16 09:16:53 2013 - ERROR - Connecting to sensor - MY IP: URLError:

I dug in deeper and I think its barking at the negotiation of SSL?
/splunk/lib/python2.7/ssl.py

I changed ssl.py ssl_version=PROTOCOL_SSLv23 to ssl_version=PROTOCOL_TLSv1 and still did not work.
I hope to get this online ASAP.

Tags (1)
0 Karma

dshpritz
SplunkTrust
SplunkTrust

You may want to check out my answer here: http://answers.splunk.com/answers/105193/cisco-ips-error-errno-8/135759. I posted some code that may solve this issue for you.

0 Karma

seanp
Path Finder

I had the same issue doing a new install on Splunk 6. I ended up having to install a Splunk 5.0.5 lightweight forwarder on a separate server and forward it to the central server. When I ran

openssl s_client -connect :443

with the version that is included in Splunk 6 but works fine in version 5.0.5. There seems to be an issue with this on Linux, however I experience the same issue with Windows

http://answers.splunk.com/answers/105193/cisco-ips-error-errno-8

0 Karma

seanp
Path Finder

I tried the very hackish replacing of the OpenSSL binary files in the bin directory with 0.9.8y but only got errors.

0 Karma

jgauthier
Contributor

I was just uncovering this mess. Wouldn't it be possible to include another openssl library somewhere and reference that?

0 Karma

jgauthier
Contributor

Mine is also broken after upgrading. I am still diagnosing this.

0 Karma
Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...