<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Verifying Secure Communication between forwarders and indexers in Security</title>
    <link>https://community.splunk.com/t5/Security/Verifying-Secure-Communication-between-forwarders-and-indexers/m-p/448110#M10489</link>
    <description>&lt;P&gt;@anoopdi : Did you get any confirmation on this?&lt;/P&gt;</description>
    <pubDate>Thu, 21 May 2020 14:49:48 GMT</pubDate>
    <dc:creator>ansif</dc:creator>
    <dc:date>2020-05-21T14:49:48Z</dc:date>
    <item>
      <title>Verifying Secure Communication between forwarders and indexers</title>
      <link>https://community.splunk.com/t5/Security/Verifying-Secure-Communication-between-forwarders-and-indexers/m-p/448107#M10486</link>
      <description>&lt;P&gt;I recently enabled SSL connection between forwarders and indexers. When I check the metrics log for a UF with SSL enabled , i see this in the data. The connection type is showing as cookedSSL but ssl=fasle. Does that mean the connection is not secure? And the surprising part is, i see events in metrics.log for the same host with ssl=true entries.  I am confused.&lt;/P&gt;

&lt;P&gt;08-15-2019 16:10:56.061 +0000 INFO  Metrics - group=tcpin_connections, xx.zz.yy.xx:52306:9997, connectionType=cookedSSL, sourcePort=52306, sourceHost=10.176.240.50, sourceIp=10.176.240.50, destPort=9997, kb=0.33, _tcp_Bps=10.97, _tcp_KBps=0.01, _tcp_avg_thruput=1.19, _tcp_Kprocessed=158.37, _tcp_eps=0.03, _process_time_ms=0, evt_misc_kBps=0.00, evt_raw_kBps=0.00, evt_fields_kBps=0.00, evt_fn_kBps=0.00, evt_fv_kBps=0.00, evt_fn_str_kBps=0.00, evt_fn_meta_dyn_kBps=0.00, evt_fn_meta_predef_kBps=0.00, evt_fn_meta_str_kBps=0.00, evt_fv_num_kBps=0.00, evt_fv_str_kBps=0.00, evt_fv_predef_kBps=0.00, evt_fv_offlen_kBps=0.00, evt_fv_fp_kBps=0.00, build=f817a93effc2, version=7.2.7, os=Linux, arch=x86_64, hostname=deployer, guid=6C69F32A-8F26-4F9F-831D-CA1623C5FA4A, fwdType=full, ssl=false, lastIndexer="10.176.240.39:9997,10.176.240.85:9997", ack=true&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 01:45:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Verifying-Secure-Communication-between-forwarders-and-indexers/m-p/448107#M10486</guid>
      <dc:creator>anoopdi</dc:creator>
      <dc:date>2020-09-30T01:45:00Z</dc:date>
    </item>
    <item>
      <title>Re: Verifying Secure Communication between forwarders and indexers</title>
      <link>https://community.splunk.com/t5/Security/Verifying-Secure-Communication-between-forwarders-and-indexers/m-p/448108#M10487</link>
      <description>&lt;P&gt;See this:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.1/Security/Validateyourconfiguration"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.1/Security/Validateyourconfiguration&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 17:41:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Verifying-Secure-Communication-between-forwarders-and-indexers/m-p/448108#M10487</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-08-15T17:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: Verifying Secure Communication between forwarders and indexers</title>
      <link>https://community.splunk.com/t5/Security/Verifying-Secure-Communication-between-forwarders-and-indexers/m-p/448109#M10488</link>
      <description>&lt;P&gt;i was using that link for the verification that's where I noticed that log. I dont see any errors in splunkd.log about SSL, both on indexers and forwarders. I think the secure communication is working but wanted to confirm that.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 18:05:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Verifying-Secure-Communication-between-forwarders-and-indexers/m-p/448109#M10488</guid>
      <dc:creator>anoopdi</dc:creator>
      <dc:date>2019-08-15T18:05:31Z</dc:date>
    </item>
    <item>
      <title>Re: Verifying Secure Communication between forwarders and indexers</title>
      <link>https://community.splunk.com/t5/Security/Verifying-Secure-Communication-between-forwarders-and-indexers/m-p/448110#M10489</link>
      <description>&lt;P&gt;@anoopdi : Did you get any confirmation on this?&lt;/P&gt;</description>
      <pubDate>Thu, 21 May 2020 14:49:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Verifying-Secure-Communication-between-forwarders-and-indexers/m-p/448110#M10489</guid>
      <dc:creator>ansif</dc:creator>
      <dc:date>2020-05-21T14:49:48Z</dc:date>
    </item>
    <item>
      <title>Re: Verifying Secure Communication between forwarders and indexers</title>
      <link>https://community.splunk.com/t5/Security/Verifying-Secure-Communication-between-forwarders-and-indexers/m-p/448111#M10490</link>
      <description>&lt;P&gt;To verify, please run this search on the SH (if all nodes are sending their internal logs to the indexing layer) : &lt;BR /&gt;
index=_internal source=&lt;EM&gt;metrics.log&lt;/EM&gt; group=tcpin_connections | &lt;BR /&gt;
dedup hostname | table _time hostname version sourceIp destPort ssl&lt;/P&gt;

&lt;P&gt;alternatively you can check manually verify the port using the openssl suite: &lt;BR /&gt;
/opt/splunk/bin/splunk cmd openssl s_client -connect :&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.1/Security/Validateyourconfiguration" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.1/Security/Validateyourconfiguration&lt;/A&gt;&lt;BR /&gt;
Hope this helps!&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 05:31:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Verifying-Secure-Communication-between-forwarders-and-indexers/m-p/448111#M10490</guid>
      <dc:creator>mguhad</dc:creator>
      <dc:date>2020-09-30T05:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: Verifying Secure Communication between forwarders and indexers</title>
      <link>https://community.splunk.com/t5/Security/Verifying-Secure-Communication-between-forwarders-and-indexers/m-p/578841#M15790</link>
      <description>&lt;P&gt;Hey anoopdi,&lt;BR /&gt;&lt;BR /&gt;Did you get any clarity with whether the communication is been secured or no ? Because I am getting the exact entries in the internal logs. (connectionType=cookedSSL but SSL=false sometimes and SSL=true sometimes).&lt;/P&gt;</description>
      <pubDate>Sun, 19 Dec 2021 07:24:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Verifying-Secure-Communication-between-forwarders-and-indexers/m-p/578841#M15790</guid>
      <dc:creator>aaditi25</dc:creator>
      <dc:date>2021-12-19T07:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: Verifying Secure Communication between forwarders and indexers</title>
      <link>https://community.splunk.com/t5/Security/Verifying-Secure-Communication-between-forwarders-and-indexers/m-p/669411#M17404</link>
      <description>&lt;P&gt;Is the forwarder using indexer discovery ?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 04:29:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Verifying-Secure-Communication-between-forwarders-and-indexers/m-p/669411#M17404</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2023-11-22T04:29:50Z</dc:date>
    </item>
  </channel>
</rss>

