<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can Splunk provide forwarding/receiving security ?? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-Splunk-provide-forwarding-receiving-security/m-p/447230#M77792</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I know there are 2 ways to secure indexer port 9997 (Or any other receiving port), you can use SSL certificate which you need to configure on Indexer and Forwarder. Please look at documentation &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.2.1/Security/Aboutsecuringdatafromforwarders"&gt;http://docs.splunk.com/Documentation/Splunk/7.2.1/Security/Aboutsecuringdatafromforwarders&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Other way is to secure Indexer and Forwarder using &lt;CODE&gt;Token&lt;/CODE&gt; but I never tried this, have a look at outputs.conf for Forwarder config&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;token = &amp;lt;string&amp;gt;
* The access token for receiving data.
* Optional.
* If you configured an access token for receiving data from a forwarder, 
  Splunk software populates that token here.
* If you configured a receiver with an access token and that token is not
  specified here, the receiver rejects all data sent to it.
* No default.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and look at inputs.conf for Indexer.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;# Access control settings.
[splunktcptoken://&amp;lt;token name&amp;gt;]
* Use this stanza to specify forwarders from which to accept data.
* You must configure a token on the receiver, then configure the same
  token on forwarders.
* The receiver discards data from forwarders that do not have the
  token configured.
* This setting is enabled for all receiving ports.
* This setting is optional.

token = &amp;lt;string&amp;gt;
* Value of token.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 14 Dec 2018 09:57:31 GMT</pubDate>
    <dc:creator>harsmarvania57</dc:creator>
    <dc:date>2018-12-14T09:57:31Z</dc:date>
    <item>
      <title>How can Splunk provide forwarding/receiving security ??</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-Splunk-provide-forwarding-receiving-security/m-p/447229#M77791</link>
      <description>&lt;P&gt;When enabling the receiving function in a Splunk Enterprise instance (indexer for example), it will be listening on port 9997 by default (changeable) and any forwarder with the information (indexer IP:port ) can forward data and it will be well received.&lt;/P&gt;

&lt;P&gt;My question here is: I think i am missing something but...&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;If a forwarder is a malicious or external one that can infect or disable the whole process by sending a massive storage ??&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;How can Splunk provide forwarding/receiving security (authentication / authorization ) ??&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Dec 2018 09:45:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-Splunk-provide-forwarding-receiving-security/m-p/447229#M77791</guid>
      <dc:creator>arlakathena</dc:creator>
      <dc:date>2018-12-14T09:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: How can Splunk provide forwarding/receiving security ??</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-Splunk-provide-forwarding-receiving-security/m-p/447230#M77792</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I know there are 2 ways to secure indexer port 9997 (Or any other receiving port), you can use SSL certificate which you need to configure on Indexer and Forwarder. Please look at documentation &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.2.1/Security/Aboutsecuringdatafromforwarders"&gt;http://docs.splunk.com/Documentation/Splunk/7.2.1/Security/Aboutsecuringdatafromforwarders&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Other way is to secure Indexer and Forwarder using &lt;CODE&gt;Token&lt;/CODE&gt; but I never tried this, have a look at outputs.conf for Forwarder config&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;token = &amp;lt;string&amp;gt;
* The access token for receiving data.
* Optional.
* If you configured an access token for receiving data from a forwarder, 
  Splunk software populates that token here.
* If you configured a receiver with an access token and that token is not
  specified here, the receiver rejects all data sent to it.
* No default.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;and look at inputs.conf for Indexer.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;# Access control settings.
[splunktcptoken://&amp;lt;token name&amp;gt;]
* Use this stanza to specify forwarders from which to accept data.
* You must configure a token on the receiver, then configure the same
  token on forwarders.
* The receiver discards data from forwarders that do not have the
  token configured.
* This setting is enabled for all receiving ports.
* This setting is optional.

token = &amp;lt;string&amp;gt;
* Value of token.
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 14 Dec 2018 09:57:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-Splunk-provide-forwarding-receiving-security/m-p/447230#M77792</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2018-12-14T09:57:31Z</dc:date>
    </item>
  </channel>
</rss>

