<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to transfer data from the data source to forwarder via syslog over TLS? in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-transfer-data-from-the-data-source-to-forwarder-via/m-p/590118#M11876</link>
    <description>&lt;P&gt;Ok, some things need clarification. Whereas TCP or HTTP are relatively strict terms, syslog is a very loosely applied name regarding to - depending on context - many things from completely anything sent to UDP/514 to a particular RFC5424 message format.&lt;/P&gt;&lt;P&gt;Most probably by saying "syslog over TLS" you mean a simple tcp-tls-based input regardless of what's being sent there.&lt;/P&gt;&lt;P&gt;Yes, it can be done. Just use tcp-tls: input instead of tcp:. Parameters regarding encryption/authentication not specified within particular input will be pulled from defaul [SSL] stanza.&lt;/P&gt;&lt;P&gt;In case of simple network inputs however, it's often worth considering setting up intermediate syslog-processing layer (sc4s, rsyslog...) to keep the network-level metadata.&lt;/P&gt;&lt;P&gt;And yes, technicaly speaking, you could of course use the splunk's internal certificates but it's generally good idea to use your own CA in production environment.&lt;/P&gt;</description>
    <pubDate>Tue, 22 Mar 2022 06:17:29 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2022-03-22T06:17:29Z</dc:date>
    <item>
      <title>How to transfer data from the data source to forwarder via syslog over TLS?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-transfer-data-from-the-data-source-to-forwarder-via/m-p/590101#M11869</link>
      <description>&lt;P&gt;I would like to transfer data from the data source to Forwarder via Syslog over TLS.&lt;BR /&gt;Is it possible to use the default SSL certificate provided by Splunk to transfer data from the data source to the forwarder over Syslog over TLS?&lt;BR /&gt;Is it possible to use the default SSL certificate provided by Splunk on non-Splunk equipment?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 05:25:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-transfer-data-from-the-data-source-to-forwarder-via/m-p/590101#M11869</guid>
      <dc:creator>AHA-0114</dc:creator>
      <dc:date>2022-03-22T05:25:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to transfer data from the data source to forwarder via syslog over TLS?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-transfer-data-from-the-data-source-to-forwarder-via/m-p/590109#M11872</link>
      <description>&lt;P&gt;I'm not a Syslog expert but if you are using rsyslog then this (&lt;A href="https://www.rsyslog.com/doc/v8-stable/tutorials/tls_cert_summary.html" target="_blank"&gt;https://www.rsyslog.com/doc/v8-stable/tutorials/tls_cert_summary.html&lt;/A&gt;) document might be useful.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 05:40:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-transfer-data-from-the-data-source-to-forwarder-via/m-p/590109#M11872</guid>
      <dc:creator>VatsalJagani</dc:creator>
      <dc:date>2022-03-22T05:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to transfer data from the data source to forwarder via syslog over TLS?</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/How-to-transfer-data-from-the-data-source-to-forwarder-via/m-p/590118#M11876</link>
      <description>&lt;P&gt;Ok, some things need clarification. Whereas TCP or HTTP are relatively strict terms, syslog is a very loosely applied name regarding to - depending on context - many things from completely anything sent to UDP/514 to a particular RFC5424 message format.&lt;/P&gt;&lt;P&gt;Most probably by saying "syslog over TLS" you mean a simple tcp-tls-based input regardless of what's being sent there.&lt;/P&gt;&lt;P&gt;Yes, it can be done. Just use tcp-tls: input instead of tcp:. Parameters regarding encryption/authentication not specified within particular input will be pulled from defaul [SSL] stanza.&lt;/P&gt;&lt;P&gt;In case of simple network inputs however, it's often worth considering setting up intermediate syslog-processing layer (sc4s, rsyslog...) to keep the network-level metadata.&lt;/P&gt;&lt;P&gt;And yes, technicaly speaking, you could of course use the splunk's internal certificates but it's generally good idea to use your own CA in production environment.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 06:17:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/How-to-transfer-data-from-the-data-source-to-forwarder-via/m-p/590118#M11876</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-22T06:17:29Z</dc:date>
    </item>
  </channel>
</rss>

