<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Forwarder SSL compression don't work in Security</title>
    <link>https://community.splunk.com/t5/Security/Forwarder-SSL-compression-don-t-work/m-p/389140#M9492</link>
    <description>&lt;P&gt;Hi Splunkers!&lt;/P&gt;

&lt;P&gt;i'm trying to configure SSL compression beetween Forwarders &amp;amp; Indexers with default cert but the compression seem doesn't working.&lt;BR /&gt;
On Indexer splunkd.log the flag useCompression is set to N --&amp;gt; useCompression=N and don't write the line "INFO TcpInputProc - Port 9998 is compressed" (based on &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.0/Security/Validateyourconfiguration):"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.0/Security/Validateyourconfiguration):&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;07-16-2019 12:18:06.615 +0200 DEBUG TcpInputConfig - stanza="SSL", rootCAPath="C:\Program Files\Splunk\etc\auth\cacert.pem", certFile="C:\Program Files\Splunk\etc\auth\server.pem", privateKeyFile="C:\Program Files\Splunk\etc\auth\server.pem", privateKeyPassword_set=Y, commonNameToCheck="", altNameToCheck="", allowSslRenegotiation=Y, sslVersions="SSL3,TLS1.0,TLS1.1,TLS1.2", cipherSuite="ALL:!aNULL:!eNULL:!LOW:!EXP:RC4+RSA:+HIGH:+MEDIUM", ecdhCurves="prime256v1, secp384r1, secp521r1", dhFile="", useCompression=N, quietShutdown=N&lt;BR /&gt;
07-16-2019 12:18:06.625 +0200 DEBUG TcpInputConfig -  Attempting to load token cache&lt;BR /&gt;
07-16-2019 12:18:06.625 +0200 INFO  TcpInputConfig - IPv4 port 9998 is reserved for splunk 2 splunk (SSL)&lt;BR /&gt;
07-16-2019 12:18:06.625 +0200 INFO  TcpInputConfig - IPv4 port 9998 will negotiate s2s protocol level 4&lt;BR /&gt;
07-16-2019 12:18:06.626 +0200 DEBUG TcpInputConfig - global prop rdnsMaxDutyCycle=10&lt;/P&gt;

&lt;P&gt;Any idea on what to check?&lt;/P&gt;

&lt;P&gt;Thanks &lt;/P&gt;</description>
    <pubDate>Tue, 16 Jul 2019 11:23:27 GMT</pubDate>
    <dc:creator>Viaris</dc:creator>
    <dc:date>2019-07-16T11:23:27Z</dc:date>
    <item>
      <title>Forwarder SSL compression don't work</title>
      <link>https://community.splunk.com/t5/Security/Forwarder-SSL-compression-don-t-work/m-p/389140#M9492</link>
      <description>&lt;P&gt;Hi Splunkers!&lt;/P&gt;

&lt;P&gt;i'm trying to configure SSL compression beetween Forwarders &amp;amp; Indexers with default cert but the compression seem doesn't working.&lt;BR /&gt;
On Indexer splunkd.log the flag useCompression is set to N --&amp;gt; useCompression=N and don't write the line "INFO TcpInputProc - Port 9998 is compressed" (based on &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.0/Security/Validateyourconfiguration):"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.0/Security/Validateyourconfiguration):&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;07-16-2019 12:18:06.615 +0200 DEBUG TcpInputConfig - stanza="SSL", rootCAPath="C:\Program Files\Splunk\etc\auth\cacert.pem", certFile="C:\Program Files\Splunk\etc\auth\server.pem", privateKeyFile="C:\Program Files\Splunk\etc\auth\server.pem", privateKeyPassword_set=Y, commonNameToCheck="", altNameToCheck="", allowSslRenegotiation=Y, sslVersions="SSL3,TLS1.0,TLS1.1,TLS1.2", cipherSuite="ALL:!aNULL:!eNULL:!LOW:!EXP:RC4+RSA:+HIGH:+MEDIUM", ecdhCurves="prime256v1, secp384r1, secp521r1", dhFile="", useCompression=N, quietShutdown=N&lt;BR /&gt;
07-16-2019 12:18:06.625 +0200 DEBUG TcpInputConfig -  Attempting to load token cache&lt;BR /&gt;
07-16-2019 12:18:06.625 +0200 INFO  TcpInputConfig - IPv4 port 9998 is reserved for splunk 2 splunk (SSL)&lt;BR /&gt;
07-16-2019 12:18:06.625 +0200 INFO  TcpInputConfig - IPv4 port 9998 will negotiate s2s protocol level 4&lt;BR /&gt;
07-16-2019 12:18:06.626 +0200 DEBUG TcpInputConfig - global prop rdnsMaxDutyCycle=10&lt;/P&gt;

&lt;P&gt;Any idea on what to check?&lt;/P&gt;

&lt;P&gt;Thanks &lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2019 11:23:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forwarder-SSL-compression-don-t-work/m-p/389140#M9492</guid>
      <dc:creator>Viaris</dc:creator>
      <dc:date>2019-07-16T11:23:27Z</dc:date>
    </item>
  </channel>
</rss>

