<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secure transport of log files to our Splunk Server in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Secure-transport-of-log-files-to-our-Splunk-Server/m-p/13099#M1138</link>
    <description>&lt;P&gt;Maybe next gen syslog.&lt;/P&gt;

&lt;P&gt;Syslog but over a TCP connection.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.debianhelp.co.uk/syslog-ng.htm"&gt;http://www.debianhelp.co.uk/syslog-ng.htm&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 07 May 2010 18:58:52 GMT</pubDate>
    <dc:creator>CerielTjuh</dc:creator>
    <dc:date>2010-05-07T18:58:52Z</dc:date>
    <item>
      <title>Secure transport of log files to our Splunk Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Secure-transport-of-log-files-to-our-Splunk-Server/m-p/13096#M1135</link>
      <description>&lt;P&gt;How do I secure my log file stream from our primary server to our dedicated Splunk server? Are there any secured layers I can use for the TCP transport?&lt;/P&gt;

&lt;P&gt;I have tried to do it with an SSH-tunnel, but when the tunnel breaks down, the next message going through the tunnel is lost.&lt;/P&gt;

&lt;P&gt;What do you do?&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2010 14:39:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Secure-transport-of-log-files-to-our-Splunk-Server/m-p/13096#M1135</guid>
      <dc:creator>sipapress2go</dc:creator>
      <dc:date>2010-05-07T14:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: Secure transport of log files to our Splunk Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Secure-transport-of-log-files-to-our-Splunk-Server/m-p/13097#M1136</link>
      <description>&lt;P&gt;Im not sure if this is what you mean but:&lt;/P&gt;

&lt;P&gt;If the primary server is a windows server you could use a splunk forwarder with ssl connection, this will ensure data transport and data integrity.
(does not require a extra license, forwarder licenses are free)&lt;/P&gt;

&lt;P&gt;If the primary server is not a windows server, try a secure FTP connection to transfer the files to the splunk server.&lt;/P&gt;

&lt;P&gt;The first method is approved by our SAS70 compliancy auditors, so should work for you as well &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2010 16:17:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Secure-transport-of-log-files-to-our-Splunk-Server/m-p/13097#M1136</guid>
      <dc:creator>CerielTjuh</dc:creator>
      <dc:date>2010-05-07T16:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: Secure transport of log files to our Splunk Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Secure-transport-of-log-files-to-our-Splunk-Server/m-p/13098#M1137</link>
      <description>&lt;P&gt;Both servers run Debian and also I want to be able to follow progress of the primary server in close to realtime (with a delay of max 10 sec.).&lt;/P&gt;

&lt;P&gt;Perhaps rsyslog is something I should look into?&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2010 16:28:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Secure-transport-of-log-files-to-our-Splunk-Server/m-p/13098#M1137</guid>
      <dc:creator>sipapress2go</dc:creator>
      <dc:date>2010-05-07T16:28:06Z</dc:date>
    </item>
    <item>
      <title>Re: Secure transport of log files to our Splunk Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Secure-transport-of-log-files-to-our-Splunk-Server/m-p/13099#M1138</link>
      <description>&lt;P&gt;Maybe next gen syslog.&lt;/P&gt;

&lt;P&gt;Syslog but over a TCP connection.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://www.debianhelp.co.uk/syslog-ng.htm"&gt;http://www.debianhelp.co.uk/syslog-ng.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2010 18:58:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Secure-transport-of-log-files-to-our-Splunk-Server/m-p/13099#M1138</guid>
      <dc:creator>CerielTjuh</dc:creator>
      <dc:date>2010-05-07T18:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: Secure transport of log files to our Splunk Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Secure-transport-of-log-files-to-our-Splunk-Server/m-p/13100#M1139</link>
      <description>&lt;P&gt;Use a Splunk forwarder, configured in SSL mode.  This is considered the best practice.&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2010 22:09:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Secure-transport-of-log-files-to-our-Splunk-Server/m-p/13100#M1139</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2010-05-07T22:09:45Z</dc:date>
    </item>
    <item>
      <title>Re: Secure transport of log files to our Splunk Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Secure-transport-of-log-files-to-our-Splunk-Server/m-p/13101#M1140</link>
      <description>&lt;P&gt;Splunk forwarders can encrypt their communication with the indexer using SSL, this can also be used to authenticate the forwarders which will prevent unauthorized forwarders from polluting your index.  Documentation on how to configure encryption and authentication of forwarders using SSL can be found &lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/EncryptandauthenticatedatawithSSL" rel="nofollow"&gt;here&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2010 23:47:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Secure-transport-of-log-files-to-our-Splunk-Server/m-p/13101#M1140</guid>
      <dc:creator>matt</dc:creator>
      <dc:date>2010-05-07T23:47:10Z</dc:date>
    </item>
    <item>
      <title>Re: Secure transport of log files to our Splunk Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Secure-transport-of-log-files-to-our-Splunk-Server/m-p/13102#M1141</link>
      <description>&lt;P&gt;the splunk forwarder with ssl will work between any two platforms on which splunk runs, which includes most unixes, linux, and windows. rsyslog is fine too, but you're more on your own with respect to setting up matching certificates, etc.&lt;/P&gt;</description>
      <pubDate>Fri, 07 May 2010 23:55:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Secure-transport-of-log-files-to-our-Splunk-Server/m-p/13102#M1141</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-05-07T23:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: Secure transport of log files to our Splunk Server</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Secure-transport-of-log-files-to-our-Splunk-Server/m-p/13103#M1142</link>
      <description>&lt;P&gt;true gkanapathy &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 May 2010 13:43:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Secure-transport-of-log-files-to-our-Splunk-Server/m-p/13103#M1142</guid>
      <dc:creator>CerielTjuh</dc:creator>
      <dc:date>2010-05-10T13:43:52Z</dc:date>
    </item>
  </channel>
</rss>

