<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to establish secure connection between Universal Forwarders and Heavy Forwarders in a distributed environment? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-establish-secure-connection-between-Universal-Forwarders/m-p/431734#M75541</link>
    <description>&lt;P&gt;Take a look at this excellent presentation from .conf15 which walks you through creating and applying certificates across all of your Splunk infrastructure:&lt;/P&gt;

&lt;P&gt;Slide 18+ covers Forwarders.&lt;BR /&gt;
&lt;A href="https://conf.splunk.com/session/2015/conf2015_DWaddle_DefensePointSecurity_deploying_SplunkSSLBestPractices.pdf"&gt;https://conf.splunk.com/session/2015/conf2015_DWaddle_DefensePointSecurity_deploying_SplunkSSLBestPractices.pdf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You can create one certificate which all your UFs will use, you don't need 200 certs!&lt;/P&gt;</description>
    <pubDate>Thu, 14 Mar 2019 11:05:24 GMT</pubDate>
    <dc:creator>nickhills</dc:creator>
    <dc:date>2019-03-14T11:05:24Z</dc:date>
    <item>
      <title>How to establish secure connection between Universal Forwarders and Heavy Forwarders in a distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-establish-secure-connection-between-Universal-Forwarders/m-p/431732#M75539</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Good day!&lt;/P&gt;

&lt;P&gt;We have distributed Splunk Enterprise setup, we are trying to establish secure SSL communication between UF-&amp;gt; HF-&amp;gt; Indexer.&lt;BR /&gt;
We do have certificates configured for Search heads, Indexers and Heavy Forwarders. We have also opened required receiving ports on both Indexer and HF.&lt;BR /&gt;
On the other hand, we have around 200 UF's, can someone please tell me, if we need to generate 200 client certificates or we can use general certificate which we can deploy on all 200 UF's for establishing communication between UF and HF.&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
D Vijaya&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 07:01:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-establish-secure-connection-between-Universal-Forwarders/m-p/431732#M75539</guid>
      <dc:creator>hartley</dc:creator>
      <dc:date>2019-03-14T07:01:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to establish secure connection between Universal Forwarders and Heavy Forwarders in a distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-establish-secure-connection-between-Universal-Forwarders/m-p/431733#M75540</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;You can use common certificate on all 200 UF which will connect with HF/IDX.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 11:04:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-establish-secure-connection-between-Universal-Forwarders/m-p/431733#M75540</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2019-03-14T11:04:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to establish secure connection between Universal Forwarders and Heavy Forwarders in a distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-establish-secure-connection-between-Universal-Forwarders/m-p/431734#M75541</link>
      <description>&lt;P&gt;Take a look at this excellent presentation from .conf15 which walks you through creating and applying certificates across all of your Splunk infrastructure:&lt;/P&gt;

&lt;P&gt;Slide 18+ covers Forwarders.&lt;BR /&gt;
&lt;A href="https://conf.splunk.com/session/2015/conf2015_DWaddle_DefensePointSecurity_deploying_SplunkSSLBestPractices.pdf"&gt;https://conf.splunk.com/session/2015/conf2015_DWaddle_DefensePointSecurity_deploying_SplunkSSLBestPractices.pdf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You can create one certificate which all your UFs will use, you don't need 200 certs!&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 11:05:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-establish-secure-connection-between-Universal-Forwarders/m-p/431734#M75541</guid>
      <dc:creator>nickhills</dc:creator>
      <dc:date>2019-03-14T11:05:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to establish secure connection between Universal Forwarders and Heavy Forwarders in a distributed environment?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-establish-secure-connection-between-Universal-Forwarders/m-p/431735#M75542</link>
      <description>&lt;P&gt;Thanks guys.. your response would help &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2019 13:13:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-establish-secure-connection-between-Universal-Forwarders/m-p/431735#M75542</guid>
      <dc:creator>hartley</dc:creator>
      <dc:date>2019-03-14T13:13:24Z</dc:date>
    </item>
  </channel>
</rss>

