<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Decode Logs coming from Syslog (SSL) in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Decode-Logs-coming-from-Syslog-SSL/m-p/319260#M59641</link>
    <description>&lt;P&gt;Splunk wont be able to decrypt this. You're going to want to use rsyslog/syslog-ng to do this, and after the files are decrypted and written to disk, use the UF to read the files.&lt;/P&gt;</description>
    <pubDate>Thu, 07 Sep 2017 06:35:51 GMT</pubDate>
    <dc:creator>esix_splunk</dc:creator>
    <dc:date>2017-09-07T06:35:51Z</dc:date>
    <item>
      <title>Decode Logs coming from Syslog (SSL)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Decode-Logs-coming-from-Syslog-SSL/m-p/319257#M59638</link>
      <description>&lt;P&gt;Hi, &lt;BR /&gt;
i am trying to send encrypted logs from Syslog to Splunk. To decrypt them i changed the splunk/etc/system/local/inputs.conf file like so:&lt;BR /&gt;
[tcp-ssl:5140]&lt;BR /&gt;
[SSL]&lt;BR /&gt;
serverCert = path.pem&lt;BR /&gt;
sslPassword = password &lt;/P&gt;

&lt;P&gt;I already get the encrypted Logs but the decryption doesnt work. &lt;BR /&gt;
Can you help me? &lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 14:37:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Decode-Logs-coming-from-Syslog-SSL/m-p/319257#M59638</guid>
      <dc:creator>elli_i</dc:creator>
      <dc:date>2017-09-06T14:37:18Z</dc:date>
    </item>
    <item>
      <title>Re: Decode Logs coming from Syslog (SSL)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Decode-Logs-coming-from-Syslog-SSL/m-p/319258#M59639</link>
      <description>&lt;P&gt;The tcp-ssl stanza just enables ssl on the connection from the syslog server to the splunk server.  It's not going to handle any decryption of the underlying data.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 16:24:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Decode-Logs-coming-from-Syslog-SSL/m-p/319258#M59639</guid>
      <dc:creator>jkat54</dc:creator>
      <dc:date>2017-09-06T16:24:59Z</dc:date>
    </item>
    <item>
      <title>Re: Decode Logs coming from Syslog (SSL)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Decode-Logs-coming-from-Syslog-SSL/m-p/319259#M59640</link>
      <description>&lt;P&gt;Okay, thanks! And what handles the decryption? I thought by sharing the certificate, with the ssl stanza, decryption is enabled. Or do i have to add a personal script? If so, is there a possibility, to just point splunk to the script, and splunk handles it? &lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 06:02:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Decode-Logs-coming-from-Syslog-SSL/m-p/319259#M59640</guid>
      <dc:creator>elli_i</dc:creator>
      <dc:date>2017-09-07T06:02:17Z</dc:date>
    </item>
    <item>
      <title>Re: Decode Logs coming from Syslog (SSL)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Decode-Logs-coming-from-Syslog-SSL/m-p/319260#M59641</link>
      <description>&lt;P&gt;Splunk wont be able to decrypt this. You're going to want to use rsyslog/syslog-ng to do this, and after the files are decrypted and written to disk, use the UF to read the files.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Sep 2017 06:35:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Decode-Logs-coming-from-Syslog-SSL/m-p/319260#M59641</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2017-09-07T06:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: Decode Logs coming from Syslog (SSL)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Decode-Logs-coming-from-Syslog-SSL/m-p/319261#M59642</link>
      <description>&lt;P&gt;I know has been long time, were you able to decryp the logs at the end?&lt;/P&gt;</description>
      <pubDate>Tue, 19 May 2020 21:28:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Decode-Logs-coming-from-Syslog-SSL/m-p/319261#M59642</guid>
      <dc:creator>crendon_splunk</dc:creator>
      <dc:date>2020-05-19T21:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: Decode Logs coming from Syslog (SSL)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Decode-Logs-coming-from-Syslog-SSL/m-p/540047#M90432</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/202391" target="_blank"&gt;@esix_splunk&lt;/A&gt;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is the above state still true with newer version of Splunk. Can Splunk decrypt the encrypted data coming from external?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 05:23:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Decode-Logs-coming-from-Syslog-SSL/m-p/540047#M90432</guid>
      <dc:creator>saravanan90</dc:creator>
      <dc:date>2021-02-16T05:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: Decode Logs coming from Syslog (SSL)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Decode-Logs-coming-from-Syslog-SSL/m-p/540048#M90433</link>
      <description>&lt;P&gt;Same still holds true, you cannot send SSL traffic to a Splunk-SSLTCP input and hope Splunk can decrypt it.&lt;/P&gt;&lt;P&gt;Splunk TCP/SSL is for Splunk2Splunk(S2S) over SSL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 05:31:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Decode-Logs-coming-from-Syslog-SSL/m-p/540048#M90433</guid>
      <dc:creator>esix_splunk</dc:creator>
      <dc:date>2021-02-16T05:31:41Z</dc:date>
    </item>
    <item>
      <title>Re: Decode Logs coming from Syslog (SSL)</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Decode-Logs-coming-from-Syslog-SSL/m-p/540049#M90434</link>
      <description>&lt;P&gt;Thanks a lot for your quick help&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/202391"&gt;@esix_splunk&lt;/a&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 05:34:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Decode-Logs-coming-from-Syslog-SSL/m-p/540049#M90434</guid>
      <dc:creator>saravanan90</dc:creator>
      <dc:date>2021-02-16T05:34:30Z</dc:date>
    </item>
  </channel>
</rss>

