<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: encrypt splunk deployment server and client communication in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/encrypt-splunk-deployment-server-and-client-communication/m-p/130960#M26933</link>
    <description>&lt;P&gt;1: No, not unless you enable SSL.&lt;/P&gt;

&lt;P&gt;2: No, but that is part of the answer,  SSL is on port &lt;CODE&gt;9998&lt;/CODE&gt; instead of &lt;CODE&gt;9997&lt;/CODE&gt; (or maybe the other way around) so you have to change that in each forwarder's &lt;CODE&gt;deploymentclient.conf&lt;/CODE&gt; file, too.&lt;/P&gt;

&lt;P&gt;3: I do not see how &lt;CODE&gt;outputs.conf&lt;/CODE&gt; fits into &lt;CODE&gt;Deployment Server&lt;/CODE&gt; technology.&lt;/P&gt;</description>
    <pubDate>Fri, 29 May 2015 19:58:08 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2015-05-29T19:58:08Z</dc:date>
    <item>
      <title>encrypt splunk deployment server and client communication</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/encrypt-splunk-deployment-server-and-client-communication/m-p/130959#M26932</link>
      <description>&lt;P&gt;I went through security guide and blogs on splunk , but I am still not clear how to encrypt communication between  splunk deployment server and deployment client&lt;/P&gt;

&lt;P&gt;1) Does by default splunk encrypts this communication using default certificates&lt;/P&gt;

&lt;P&gt;2) if no just by adding this stanza in /opt/splunk/etc/system/local/server.conf  on deployment server will it start working.&lt;BR /&gt;&lt;BR /&gt;
[sslConfig] &lt;BR /&gt;
 enableSplunkdSSL = true &lt;BR /&gt;
 sslKeysfile = forwarder.pem &lt;BR /&gt;
 sslKeysfilePassword = password &lt;BR /&gt;
 caCertFile = cacert.pem &lt;BR /&gt;
 caPath = C:Program FilesSplunkUniversalForwarderetcappsapp-namelocal &lt;/P&gt;

&lt;P&gt;3) I see splunk answers for same topic. Some of them also mention outputs.conf on universal agent. We are configuring splunk deployment server to deployment client communication, why outputs.conf is needed for this communication. &lt;BR /&gt;
In my setup I have universal forwarder reporting to heavy forwarder and I just want to encrypt traffic between deployment client and deployment server.&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2015 19:15:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/encrypt-splunk-deployment-server-and-client-communication/m-p/130959#M26932</guid>
      <dc:creator>shaileshmali</dc:creator>
      <dc:date>2015-05-29T19:15:46Z</dc:date>
    </item>
    <item>
      <title>Re: encrypt splunk deployment server and client communication</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/encrypt-splunk-deployment-server-and-client-communication/m-p/130960#M26933</link>
      <description>&lt;P&gt;1: No, not unless you enable SSL.&lt;/P&gt;

&lt;P&gt;2: No, but that is part of the answer,  SSL is on port &lt;CODE&gt;9998&lt;/CODE&gt; instead of &lt;CODE&gt;9997&lt;/CODE&gt; (or maybe the other way around) so you have to change that in each forwarder's &lt;CODE&gt;deploymentclient.conf&lt;/CODE&gt; file, too.&lt;/P&gt;

&lt;P&gt;3: I do not see how &lt;CODE&gt;outputs.conf&lt;/CODE&gt; fits into &lt;CODE&gt;Deployment Server&lt;/CODE&gt; technology.&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2015 19:58:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/encrypt-splunk-deployment-server-and-client-communication/m-p/130960#M26933</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-05-29T19:58:08Z</dc:date>
    </item>
  </channel>
</rss>

