Forum Discussion

ST_Wong's avatar
ST_Wong
Icon for Cirrus rankCirrus
May 29, 2017

f5.analytics sends no data to Splunk?

Hello,

 

We followed steps in the guide and deploying v3.7.0 with Splunk 6.5.3. There is no event sent to Splunk. Seems the SSL handshake can't complete due to unknown CA error. See following in Splunk about complaint from LTM with v3.7.0 deployed, while there is no error logged on LTM:

 

error:14094418:SSL routines:ssl3_read_bytes:tlsv1 alert unknown ca

 

As we're using default server certs on Splunk, can we add the cert to trust CA list on LTM if this is the cause? Thanks a lot.

 

Regards

 

1 Reply

  • Just fixed the 'problem'.

     

    We've enabled indexer acknowledgment on the HTTP event collector token. This setting requires supplying a channel. The iApp doesn’t work with this option. After disabling indexer acknowledgement on Splunk, data now comes in.

     

    Thanks.