Forum Discussion
f5.analytics sends no data to Splunk?
Hello,
We followed steps in the guide and deploying v3.7.0 with Splunk 6.5.3. There is no event sent to Splunk. Seems the SSL handshake can't complete due to unknown CA error. See following in Splunk about complaint from LTM with v3.7.0 deployed, while there is no error logged on LTM:
error:14094418:SSL routines:ssl3_read_bytes:tlsv1 alert unknown ca
As we're using default server certs on Splunk, can we add the cert to trust CA list on LTM if this is the cause? Thanks a lot.
Regards
- ST_Wong
Cirrus
Just fixed the 'problem'.
We've enabled indexer acknowledgment on the HTTP event collector token. This setting requires supplying a channel. The iApp doesn’t work with this option. After disabling indexer acknowledgement on Splunk, data now comes in.
Thanks.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com