<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security reference how to secure data inbound to splunk from a monitored device in Security</title>
    <link>https://community.splunk.com/t5/Security/Security-reference-how-to-secure-data-inbound-to-splunk-from-a/m-p/668013#M17370</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/262036"&gt;@Erbrown&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;which kind of ingestions are you speaking about: forwarders, syslog, HEC?&lt;/P&gt;&lt;P&gt;if Forwarders, you can excrypt data between Forwarders and Indexers and there are checking technics inside Splunk.&lt;/P&gt;&lt;P&gt;If you're speaking of syslog: I hint to use an rsyslog server and read files using a Universal Forwarders; I'm not sure that's possible to encrypt syslogs; in addition, you could use two UFs and a Load Balancer to avoid Single Point of Failures,&lt;/P&gt;&lt;P&gt;If you're speaking of HEC, you can use https and the token is a securization of your ingestion; as syslogs, you should use two Forwarders and a Load Balancer.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 09 Nov 2023 07:13:56 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-11-09T07:13:56Z</dc:date>
    <item>
      <title>Security reference how to secure data inbound to splunk from a monitored device</title>
      <link>https://community.splunk.com/t5/Security/Security-reference-how-to-secure-data-inbound-to-splunk-from-a/m-p/667995#M17369</link>
      <description>&lt;P&gt;Hi Folks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm looking for a document that will help me understand my options for ensuring the integrity of data inbound to splunk from monitored devices, and any security options I may have there.&amp;nbsp; I know TLS is an option for inter-splunk traffic.&amp;nbsp; Unfortunately, I'm not having any luck with finding options to ensure the integrity and security of data when it's first received into splunk.&lt;/P&gt;&lt;P&gt;Surely there's a way for me to secure that, what am I missing here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 23:08:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Security-reference-how-to-secure-data-inbound-to-splunk-from-a/m-p/667995#M17369</guid>
      <dc:creator>Erbrown</dc:creator>
      <dc:date>2023-11-08T23:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: Security reference how to secure data inbound to splunk from a monitored device</title>
      <link>https://community.splunk.com/t5/Security/Security-reference-how-to-secure-data-inbound-to-splunk-from-a/m-p/668013#M17370</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/262036"&gt;@Erbrown&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;which kind of ingestions are you speaking about: forwarders, syslog, HEC?&lt;/P&gt;&lt;P&gt;if Forwarders, you can excrypt data between Forwarders and Indexers and there are checking technics inside Splunk.&lt;/P&gt;&lt;P&gt;If you're speaking of syslog: I hint to use an rsyslog server and read files using a Universal Forwarders; I'm not sure that's possible to encrypt syslogs; in addition, you could use two UFs and a Load Balancer to avoid Single Point of Failures,&lt;/P&gt;&lt;P&gt;If you're speaking of HEC, you can use https and the token is a securization of your ingestion; as syslogs, you should use two Forwarders and a Load Balancer.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 09 Nov 2023 07:13:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Security-reference-how-to-secure-data-inbound-to-splunk-from-a/m-p/668013#M17370</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-09T07:13:56Z</dc:date>
    </item>
  </channel>
</rss>

