<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is is possible to direct Insighs Infrastructure Collectd agent to send to the 9997 of a Universal Forwarder instead using HEC 8088? in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-is-possible-to-direct-Insighs-Infrastructure-Collectd-agent/m-p/399421#M48712</link>
    <description>&lt;P&gt;Hey Luis!&lt;/P&gt;

&lt;P&gt;Thanks for checking out insights for infra!!&lt;/P&gt;

&lt;P&gt;While what your asking is totally doable, - to the best of my knowledge, at least - catching HEC with UF is not officially supported. &lt;/P&gt;

&lt;P&gt;That being said, there are customers who do it and have no issues. You can chat with some of them on our slack chat, sign up here: splk.it/slack&lt;/P&gt;

&lt;P&gt;I would still like to explore the option with you and help you try it out to see if you can achieve what makes deploying easier for you!&lt;/P&gt;

&lt;P&gt;please hit me up at the email in my bio, or at @mattymo on Slack in our #insights-for-infra channel, where myself and the PM and ENG folks hang out!&lt;/P&gt;</description>
    <pubDate>Thu, 21 Jun 2018 16:32:40 GMT</pubDate>
    <dc:creator>mattymo</dc:creator>
    <dc:date>2018-06-21T16:32:40Z</dc:date>
    <item>
      <title>Is is possible to direct Insighs Infrastructure Collectd agent to send to the 9997 of a Universal Forwarder instead using HEC 8088?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-is-possible-to-direct-Insighs-Infrastructure-Collectd-agent/m-p/399420#M48711</link>
      <description>&lt;P&gt;Hi, we are trying to use Splunk Insights for Infrastructure in a large company where security policies are quite tight. By default, machines have open connections to port 9997 on Heavy Forwarders, so opening a new port on 8088 for each agent install is not practical.&lt;/P&gt;

&lt;P&gt;Is it possible to make insights CollectD agent use the Universal Forwarder, that is also in the agent machine, to send its data instead of directly sending data to the Infrastructure server using HEC on port 8088?&lt;/P&gt;

&lt;P&gt;Any other suggestions?&lt;/P&gt;

&lt;P&gt;Many thanks in advance!&lt;/P&gt;

&lt;P&gt;Luis Bontempo&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 14:54:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-is-possible-to-direct-Insighs-Infrastructure-Collectd-agent/m-p/399420#M48711</guid>
      <dc:creator>luisbontempo</dc:creator>
      <dc:date>2018-06-21T14:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: Is is possible to direct Insighs Infrastructure Collectd agent to send to the 9997 of a Universal Forwarder instead using HEC 8088?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-is-possible-to-direct-Insighs-Infrastructure-Collectd-agent/m-p/399421#M48712</link>
      <description>&lt;P&gt;Hey Luis!&lt;/P&gt;

&lt;P&gt;Thanks for checking out insights for infra!!&lt;/P&gt;

&lt;P&gt;While what your asking is totally doable, - to the best of my knowledge, at least - catching HEC with UF is not officially supported. &lt;/P&gt;

&lt;P&gt;That being said, there are customers who do it and have no issues. You can chat with some of them on our slack chat, sign up here: splk.it/slack&lt;/P&gt;

&lt;P&gt;I would still like to explore the option with you and help you try it out to see if you can achieve what makes deploying easier for you!&lt;/P&gt;

&lt;P&gt;please hit me up at the email in my bio, or at @mattymo on Slack in our #insights-for-infra channel, where myself and the PM and ENG folks hang out!&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 16:32:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-is-possible-to-direct-Insighs-Infrastructure-Collectd-agent/m-p/399421#M48712</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2018-06-21T16:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: Is is possible to direct Insighs Infrastructure Collectd agent to send to the 9997 of a Universal Forwarder instead using HEC 8088?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-is-possible-to-direct-Insighs-Infrastructure-Collectd-agent/m-p/399422#M48713</link>
      <description>&lt;P&gt;We're also looking for a similar solution!&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 11:49:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-is-possible-to-direct-Insighs-Infrastructure-Collectd-agent/m-p/399422#M48713</guid>
      <dc:creator>stefan_d</dc:creator>
      <dc:date>2018-07-17T11:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: Is is possible to direct Insighs Infrastructure Collectd agent to send to the 9997 of a Universal Forwarder instead using HEC 8088?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-is-possible-to-direct-Insighs-Infrastructure-Collectd-agent/m-p/399423#M48714</link>
      <description>&lt;P&gt;we got it working! Will Ask Luis to share his experience &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 13:08:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-is-possible-to-direct-Insighs-Infrastructure-Collectd-agent/m-p/399423#M48714</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2018-07-17T13:08:00Z</dc:date>
    </item>
    <item>
      <title>Re: Is is possible to direct Insighs Infrastructure Collectd agent to send to the 9997 of a Universal Forwarder instead using HEC 8088?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-is-possible-to-direct-Insighs-Infrastructure-Collectd-agent/m-p/399424#M48715</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;Thanks to Matthew we were able to sort this one out so here are the steps to do it.&lt;BR /&gt;
On the machine where you installed the agents do as sysadmin:&lt;/P&gt;

&lt;P&gt;Edit the agent machine universal forwarder configuration "inputs.conf" and change it to&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[http]
disabled=0
port=8088
enableSSL=0
dedicatedIoThreads=2
maxThreads = 0
maxSockets = 0
useDeploymentServer=0
# ssl settings are similar to mgmt server
sslVersions=*,-ssl2
allowSslCompression=true
allowSslRenegotiation=true


[http://uf_hec_local]
disabled = 0
token = 00000000-0000-0000-0000-000000000000
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Restart the universal forwarder&lt;BR /&gt;
&lt;CODE&gt;sudo /opt/splunkforwarder/bin/splunk restart&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Edit the CollectD agent&lt;BR /&gt;
&lt;CODE&gt;vi /etc/collectd/collectd.conf&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;server "localhost"
port "8088"
token "00000000-0000-0000-0000-000000000000"
ssl true
verifyssl false
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Restart the CollectD service&lt;BR /&gt;
&lt;CODE&gt;service collectd restart&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;SECURITY INFO:&lt;/STRONG&gt; for simplicity the token was all zeros but for security reasons best to change to another key&lt;BR /&gt;
&lt;STRONG&gt;WARNING:&lt;/STRONG&gt; This is not officially supported !&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jul 2018 13:36:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-is-possible-to-direct-Insighs-Infrastructure-Collectd-agent/m-p/399424#M48715</guid>
      <dc:creator>luisbontempo</dc:creator>
      <dc:date>2018-07-17T13:36:42Z</dc:date>
    </item>
    <item>
      <title>Re: Is is possible to direct Insighs Infrastructure Collectd agent to send to the 9997 of a Universal Forwarder instead using HEC 8088?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-is-possible-to-direct-Insighs-Infrastructure-Collectd-agent/m-p/399425#M48716</link>
      <description>&lt;P&gt;would also recommend setting hec to only listen to localhost, unless you are trying to receive remote calls to hec using &lt;CODE&gt;acceptFrom&lt;/CODE&gt; in &lt;CODE&gt;inputs.conf&lt;/CODE&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;acceptFrom =  ...
* Lists a set of networks or IP addresses from which to accept connections.
* Specify multiple rules with commas or spaces.
* Each rule can be in the following forms:
    1. A single IPv4 or IPv6 address (examples: "10.1.2.3", "fe80::4a3")
    2. A CIDR block of addresses (examples: "10/8", "fe80:1234/32")
    3. A DNS name, possibly with a '*' used as a wildcard (examples:
       "myhost.example.com", "*.splunk.com")
    4. A single '*', which matches anything.
* You can also prefix an entry with '!' to cause the rule to reject the
  connection. The input applies rules in order, and uses the first one that
  matches. For example, "!10.1/16, *" allows connections from everywhere except
  the 10.1.*.* network.
* Defaults to "*" (accept from anywhere)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 18 Jul 2018 01:59:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-is-possible-to-direct-Insighs-Infrastructure-Collectd-agent/m-p/399425#M48716</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2018-07-18T01:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: Is is possible to direct Insighs Infrastructure Collectd agent to send to the 9997 of a Universal Forwarder instead using HEC 8088?</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-is-possible-to-direct-Insighs-Infrastructure-Collectd-agent/m-p/399426#M48717</link>
      <description>&lt;P&gt;Thanks for sharing!&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2018 06:06:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Is-is-possible-to-direct-Insighs-Infrastructure-Collectd-agent/m-p/399426#M48717</guid>
      <dc:creator>stefan_d</dc:creator>
      <dc:date>2018-07-18T06:06:37Z</dc:date>
    </item>
  </channel>
</rss>

