<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Secure forwarded data with certificates. in Security</title>
    <link>https://community.splunk.com/t5/Security/Secure-forwarded-data-with-certificates/m-p/367397#M9139</link>
    <description>&lt;P&gt;Dear Members,&lt;/P&gt;

&lt;P&gt;We have a peculiar problem, there are 3 regions from which we collect data. Each region data should maintain its own integrity for various purposes.&lt;/P&gt;

&lt;P&gt;The indexers, search heads and primary deployment server are in the 4th region. Now we use a secondary deployment server in each region which poll to primary DS, the secondary DSs also act as HF to forward data to the common indexers in the 4th region.&lt;/P&gt;

&lt;P&gt;Now the requirement is to secure the forwarded data using different certificates for each location. Server certificate could be same but the client certificates should be unique for each region.&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Wed, 21 Jun 2017 13:19:31 GMT</pubDate>
    <dc:creator>allan_newton</dc:creator>
    <dc:date>2017-06-21T13:19:31Z</dc:date>
    <item>
      <title>Secure forwarded data with certificates.</title>
      <link>https://community.splunk.com/t5/Security/Secure-forwarded-data-with-certificates/m-p/367397#M9139</link>
      <description>&lt;P&gt;Dear Members,&lt;/P&gt;

&lt;P&gt;We have a peculiar problem, there are 3 regions from which we collect data. Each region data should maintain its own integrity for various purposes.&lt;/P&gt;

&lt;P&gt;The indexers, search heads and primary deployment server are in the 4th region. Now we use a secondary deployment server in each region which poll to primary DS, the secondary DSs also act as HF to forward data to the common indexers in the 4th region.&lt;/P&gt;

&lt;P&gt;Now the requirement is to secure the forwarded data using different certificates for each location. Server certificate could be same but the client certificates should be unique for each region.&lt;/P&gt;

&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2017 13:19:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Secure-forwarded-data-with-certificates/m-p/367397#M9139</guid>
      <dc:creator>allan_newton</dc:creator>
      <dc:date>2017-06-21T13:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: Secure forwarded data with certificates.</title>
      <link>https://community.splunk.com/t5/Security/Secure-forwarded-data-with-certificates/m-p/367398#M9140</link>
      <description>&lt;P&gt;You can create an app for each region that contains the proper config to use for that outputs.conf&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Security/Aboutsecuringdatafromforwarders"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Security/Aboutsecuringdatafromforwarders&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Duane Waddle and George Starcher's talk is a great primer for this topic to help supplement Splunk docs:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://wiki.splunk.com/images/f/fb/SplunkTrustApril-SSLipperySlopeRevisited.pdf"&gt;https://wiki.splunk.com/images/f/fb/SplunkTrustApril-SSLipperySlopeRevisited.pdf&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://splunk.webex.com/splunk/lsr.php?RCID=da90ccae281af46da9e4a3b46c076a0b"&gt;https://splunk.webex.com/splunk/lsr.php?RCID=da90ccae281af46da9e4a3b46c076a0b&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Just ensure each zone's HF has the cert they need from the CA that the IDX wants and you should be ok. The idx will simply check the cert the HF has, but the IDX's cert is the one that secure comms. &lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2017 13:46:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Secure-forwarded-data-with-certificates/m-p/367398#M9140</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2017-06-21T13:46:20Z</dc:date>
    </item>
  </channel>
</rss>

