Network Management

Audit Event message "Encrypted Syslog certificate error detected on engine <Engine name> from <xx.xx.xx.xx> using 'SolarWinds-Orion'. Errors: Unable to read data from the transport connection: An existing connection was forcibly closed by the remote host"

This article provides information on how to address the Encrypted Syslog Certificate Error detected on engines.

First published date

7/1/2025 5:26 PM

Last published date

7/1/2025 5:26 PM

Overview

This article provides information to address the following Error Messages that are usually observed in all audit events.

Encrypted Syslog certificate error detected on engine <Engine name> from XX.XX.XX.XX using 'SolarWinds-Orion'. Errors: Unable to read data from the transport connection: An existing connection was forcibly closed by the remote host.

 

Encrypted Syslog certificate error detected on engine <Engine name> from XX.XX.XX.XX using 'SolarWinds-Orion'. Errors: The handshake failed due to an unexpected packet format.

 

Encrypted Syslog certificate error detected on engine <Engine name> from XX.XX.XX.XX using 'SolarWinds-Orion'. Errors: A call to SSPI failed, see inner exception..

 

Product section

Network Performance Monitor

Cause

These error messages are usually observed in Audit Events that are caused by the TLS Server certificate for the engines, but are ignorable. 

Resolution

1. Log in to the SolarWinds Platform Web Console as an administrator.

2. Navigate to Advanced Configuration by adjusting the URL to: [hostname]/Orion/Admin/advancedconfiguration/global.aspx.

3. Search for "secureforwarding":

4. Please tick the checkbox next to SecureForwardingTlsIgnoreMissingServerCertificate

 

 

 

Once the required changes were made, please observe the issue for a few days, and these error messages will stop appearing.