Cooked connection means that somewhere along the network your SSL connection is being blocked.
Could be the indexer is not configured with the right certificate to accept encrypted connections
a firewall is blocking the connection
also remember always restart splunk after any configuration changes in order for them to take effect
To identify the cause of the problem visit:
http://www.visicoretech.com/splunk/splunk-troubleshooting-forwarder/
... View more