<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Configuring TLS for Forwarding in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Configuring-TLS-for-Forwarding/m-p/582243#M102580</link>
    <description>&lt;P&gt;I have noticed that my Splunk Enterprise 8.2.4 (all windows) indexers are listening on TCP 9997 and forwarders are forwarding payloads in plaintext across the network which security are naturally not happy with. So I'd like to use my PKI to issue some certificates for the indexer to start with (I'll worry about client certificates and mutual authentication down the line). I run a master, one search head and and indexer cluster with two nodes.&lt;/P&gt;&lt;P&gt;The guides seem to be clear enough on how to create the additional listener etc. but one thing is confusing me.&amp;nbsp; The &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.4/Security/ConfigureSplunkforwardingtousesignedcertificates" target="_blank" rel="noopener"&gt;guide&lt;/A&gt; indicates to create the SSL listener and config under&amp;nbsp;&lt;SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;$SPLUNK_HOME/etc/system/local/inputs.conf&lt;/STRONG&gt;&lt;/EM&gt; but on my indexers the existing&amp;nbsp;listener&amp;nbsp;is under&amp;nbsp; &lt;EM&gt;&lt;STRONG&gt;etc\apps\search\local\inputs.conf&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Jan 2022 11:50:01 GMT</pubDate>
    <dc:creator>shocko</dc:creator>
    <dc:date>2022-01-24T11:50:01Z</dc:date>
    <item>
      <title>Configuring TLS for Forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configuring-TLS-for-Forwarding/m-p/582243#M102580</link>
      <description>&lt;P&gt;I have noticed that my Splunk Enterprise 8.2.4 (all windows) indexers are listening on TCP 9997 and forwarders are forwarding payloads in plaintext across the network which security are naturally not happy with. So I'd like to use my PKI to issue some certificates for the indexer to start with (I'll worry about client certificates and mutual authentication down the line). I run a master, one search head and and indexer cluster with two nodes.&lt;/P&gt;&lt;P&gt;The guides seem to be clear enough on how to create the additional listener etc. but one thing is confusing me.&amp;nbsp; The &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.4/Security/ConfigureSplunkforwardingtousesignedcertificates" target="_blank" rel="noopener"&gt;guide&lt;/A&gt; indicates to create the SSL listener and config under&amp;nbsp;&lt;SPAN&gt;&lt;EM&gt;&lt;STRONG&gt;$SPLUNK_HOME/etc/system/local/inputs.conf&lt;/STRONG&gt;&lt;/EM&gt; but on my indexers the existing&amp;nbsp;listener&amp;nbsp;is under&amp;nbsp; &lt;EM&gt;&lt;STRONG&gt;etc\apps\search\local\inputs.conf&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 11:50:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configuring-TLS-for-Forwarding/m-p/582243#M102580</guid>
      <dc:creator>shocko</dc:creator>
      <dc:date>2022-01-24T11:50:01Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring TLS for Forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configuring-TLS-for-Forwarding/m-p/582250#M102582</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/191266"&gt;@shocko&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;It seems the inputs.conf is created under&amp;nbsp; /&lt;EM&gt;&lt;STRONG&gt;search/local/.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/EM&gt;this configuration also works, first&amp;nbsp; Splunk looks for config under&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;/system/local/&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;if doesnt found it looks for other directory as a part of &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.4/Admin/Wheretofindtheconfigurationfiles" target="_self"&gt;precedence&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 12:26:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configuring-TLS-for-Forwarding/m-p/582250#M102582</guid>
      <dc:creator>SanjayReddy</dc:creator>
      <dc:date>2022-01-24T12:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring TLS for Forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configuring-TLS-for-Forwarding/m-p/582322#M102593</link>
      <description>&lt;P&gt;I see no mention of the /search/ directory though in that document. Have I missed something?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 22:02:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configuring-TLS-for-Forwarding/m-p/582322#M102593</guid>
      <dc:creator>shocko</dc:creator>
      <dc:date>2022-01-24T22:02:56Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring TLS for Forwarding</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Configuring-TLS-for-Forwarding/m-p/582324#M102594</link>
      <description>&lt;P&gt;From the configuration point of view, search is just another app.&lt;/P&gt;&lt;P&gt;It's a matter of convention and convenience usually. If you prepare config files by hand you usually split them logically into apps so you might for example have an app dedicated to a particular input or input type. This way you have granular control over the resulting configuration if you push some apps to forwarders.&lt;/P&gt;&lt;P&gt;But if you're configuring your splunk instance from the webui, since you're doing it mostly in search app (if we're talking about the "generic" splunk settings), the settings land in search app's directory.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jan 2022 22:15:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Configuring-TLS-for-Forwarding/m-p/582324#M102594</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-01-24T22:15:47Z</dc:date>
    </item>
  </channel>
</rss>

