<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do i forward to multiple indexers w/SSL in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-forward-to-multiple-indexers-w-SSL/m-p/9864#M205</link>
    <description>&lt;P&gt;Forwarding to multiple indexers via SSL encryption is entirely possible.
Here's an example using a cloning configuration, in this config the SSL cert on the
forwarder is signed by both indexers and we are using the common name to provide authorization.&lt;BR /&gt;
 Remember to make sure your certs are in the specified directories on both indexers and forwarders.&lt;/P&gt;

&lt;P&gt;[tcpout]&lt;BR /&gt;
defaultGroup = index-server1, index-server2&lt;BR /&gt;
disabled = false&lt;/P&gt;

&lt;P&gt;[tcpout:index-server1]&lt;BR /&gt;
server = index1.somedomain.com:9777 &lt;/P&gt;

&lt;P&gt;[tcpout:index-server2]&lt;BR /&gt;
server = index2.somedomain.com:9777 &lt;/P&gt;

&lt;P&gt;[tcpout-server://index-server1.somedomain.com:9997]&lt;BR /&gt;
sslCertPath = $SPLUNK_HOME/etc/auth/fowarder_cert.pem&lt;BR /&gt;
sslRootCAPath = $SPLUNK_HOME/etc/auth/CAcert.pem&lt;BR /&gt;
sslVerifyServerCert = true&lt;BR /&gt;
sslCommonNameToCheck = splunk_index.somedomain.com  &lt;/P&gt;

&lt;P&gt;[tcpout-server://index-server2.somedomain.com:9997]&lt;BR /&gt;
sslCertPath = $SPLUNK_HOME/etc/auth/fowarder_cert.pem&lt;BR /&gt;
sslRootCAPath = $SPLUNK_HOME/etc/auth/CAcert.pem&lt;BR /&gt;
sslVerifyServerCert = true&lt;BR /&gt;
sslCommonNameToCheck = splunk_index.somedomain.com  &lt;/P&gt;

&lt;P&gt;For further examples on how to setup forwarding and receiving using SSL encryption 
see our official documents
&lt;A href="http://www.splunk.com/base/Documentation/4.0.9/Admin/UseSSLencryptionbetweenforwardersandreceivers" rel="nofollow"&gt;Splunk SSL documentation&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Feb 2010 08:41:07 GMT</pubDate>
    <dc:creator>Chris_R_</dc:creator>
    <dc:date>2010-02-24T08:41:07Z</dc:date>
    <item>
      <title>How do i forward to multiple indexers w/SSL</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-forward-to-multiple-indexers-w-SSL/m-p/9863#M204</link>
      <description>&lt;P&gt;I have two indexers and a (various#) number of forwarders, how can i use SSL for all traffic between these boxes?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2010 08:01:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-i-forward-to-multiple-indexers-w-SSL/m-p/9863#M204</guid>
      <dc:creator>Chris_R_</dc:creator>
      <dc:date>2010-02-24T08:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: How do i forward to multiple indexers w/SSL</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-forward-to-multiple-indexers-w-SSL/m-p/9864#M205</link>
      <description>&lt;P&gt;Forwarding to multiple indexers via SSL encryption is entirely possible.
Here's an example using a cloning configuration, in this config the SSL cert on the
forwarder is signed by both indexers and we are using the common name to provide authorization.&lt;BR /&gt;
 Remember to make sure your certs are in the specified directories on both indexers and forwarders.&lt;/P&gt;

&lt;P&gt;[tcpout]&lt;BR /&gt;
defaultGroup = index-server1, index-server2&lt;BR /&gt;
disabled = false&lt;/P&gt;

&lt;P&gt;[tcpout:index-server1]&lt;BR /&gt;
server = index1.somedomain.com:9777 &lt;/P&gt;

&lt;P&gt;[tcpout:index-server2]&lt;BR /&gt;
server = index2.somedomain.com:9777 &lt;/P&gt;

&lt;P&gt;[tcpout-server://index-server1.somedomain.com:9997]&lt;BR /&gt;
sslCertPath = $SPLUNK_HOME/etc/auth/fowarder_cert.pem&lt;BR /&gt;
sslRootCAPath = $SPLUNK_HOME/etc/auth/CAcert.pem&lt;BR /&gt;
sslVerifyServerCert = true&lt;BR /&gt;
sslCommonNameToCheck = splunk_index.somedomain.com  &lt;/P&gt;

&lt;P&gt;[tcpout-server://index-server2.somedomain.com:9997]&lt;BR /&gt;
sslCertPath = $SPLUNK_HOME/etc/auth/fowarder_cert.pem&lt;BR /&gt;
sslRootCAPath = $SPLUNK_HOME/etc/auth/CAcert.pem&lt;BR /&gt;
sslVerifyServerCert = true&lt;BR /&gt;
sslCommonNameToCheck = splunk_index.somedomain.com  &lt;/P&gt;

&lt;P&gt;For further examples on how to setup forwarding and receiving using SSL encryption 
see our official documents
&lt;A href="http://www.splunk.com/base/Documentation/4.0.9/Admin/UseSSLencryptionbetweenforwardersandreceivers" rel="nofollow"&gt;Splunk SSL documentation&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2010 08:41:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-i-forward-to-multiple-indexers-w-SSL/m-p/9864#M205</guid>
      <dc:creator>Chris_R_</dc:creator>
      <dc:date>2010-02-24T08:41:07Z</dc:date>
    </item>
    <item>
      <title>Re: How do i forward to multiple indexers w/SSL</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-forward-to-multiple-indexers-w-SSL/m-p/9865#M206</link>
      <description>&lt;P&gt;Information about setting up SSL forwarding with host authentication and self-signed certificates can be found here : &lt;A href="http://answers.splunk.com/questions/7164/how-do-i-set-up-ssl-forwarding-with-new-self-signed-certificates-and-host-authen"&gt;http://answers.splunk.com/questions/7164/how-do-i-set-up-ssl-forwarding-with-new-self-signed-certificates-and-host-authen&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2010 13:56:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-i-forward-to-multiple-indexers-w-SSL/m-p/9865#M206</guid>
      <dc:creator>hexx</dc:creator>
      <dc:date>2010-09-23T13:56:42Z</dc:date>
    </item>
  </channel>
</rss>

