<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HEC Configuration Certificate required? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Configuration-Certificate-required/m-p/580283#M102382</link>
    <description>&lt;P&gt;Thanks for the information.&amp;nbsp; &amp;nbsp;What is LB?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 07 Jan 2022 15:59:00 GMT</pubDate>
    <dc:creator>agallegos</dc:creator>
    <dc:date>2022-01-07T15:59:00Z</dc:date>
    <item>
      <title>HEC Configuration Certificate required?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Configuration-Certificate-required/m-p/580025#M102358</link>
      <description>&lt;P&gt;We have a commercial appliance that requires a HEC configuration in Splunk to ingest data.&amp;nbsp; I have configuration the TA and App and the HEC configuration on the search head.&amp;nbsp; But I get no data being ingested.&amp;nbsp; &amp;nbsp;I was told that it requires a valid certificate on the search head in order for this to work.&amp;nbsp; Is this true?&amp;nbsp; In the HEC configuration there is a check box for not using SSL.&amp;nbsp; I've also have run the curl -k command with success using the generated token.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jan 2022 16:11:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HEC-Configuration-Certificate-required/m-p/580025#M102358</guid>
      <dc:creator>agallegos</dc:creator>
      <dc:date>2022-01-05T16:11:22Z</dc:date>
    </item>
    <item>
      <title>Re: HEC Configuration Certificate required?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Configuration-Certificate-required/m-p/580273#M102381</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;it depends on client if it can use self signed certificates or work without ssl. If valid cert is required you have basically two options to manage it.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Buy it and start to use it in all splunk nodes&lt;/LI&gt;&lt;LI&gt;Use LB before HEC and install valid cert there and then you forward traffic with or without ssl to real hec nodes&lt;/LI&gt;&lt;LI&gt;If appliance support additional CAs then add your own there with possible needed intermediate certificates&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Probably the 2nd one is the easiest and quickest solution for you?&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 14:44:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HEC-Configuration-Certificate-required/m-p/580273#M102381</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-07T14:44:55Z</dc:date>
    </item>
    <item>
      <title>Re: HEC Configuration Certificate required?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Configuration-Certificate-required/m-p/580283#M102382</link>
      <description>&lt;P&gt;Thanks for the information.&amp;nbsp; &amp;nbsp;What is LB?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 15:59:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HEC-Configuration-Certificate-required/m-p/580283#M102382</guid>
      <dc:creator>agallegos</dc:creator>
      <dc:date>2022-01-07T15:59:00Z</dc:date>
    </item>
    <item>
      <title>Re: HEC Configuration Certificate required?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Configuration-Certificate-required/m-p/580290#M102384</link>
      <description>&lt;P&gt;LB is a load balancer. It could be a hardware based e.g. F5 or software based like AWS NLB or ALB.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 16:37:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HEC-Configuration-Certificate-required/m-p/580290#M102384</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-07T16:37:00Z</dc:date>
    </item>
    <item>
      <title>Re: HEC Configuration Certificate required?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/HEC-Configuration-Certificate-required/m-p/580316#M102387</link>
      <description>&lt;P&gt;Thanks for the solution.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jan 2022 22:07:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/HEC-Configuration-Certificate-required/m-p/580316#M102387</guid>
      <dc:creator>agallegos</dc:creator>
      <dc:date>2022-01-07T22:07:41Z</dc:date>
    </item>
  </channel>
</rss>

