<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk  supported S2S protocols and enableOldS2SProtocol (oldest protocol) explained in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-supported-S2S-protocols-and-enableOldS2SProtocol-oldest/m-p/741714#M10786</link>
    <description>&lt;P&gt;Are you recommending&amp;nbsp;&lt;EM&gt;&lt;FONT color="#FF6600"&gt;enableOldS2SProtocol=true&lt;/FONT&gt;&lt;/EM&gt;?&lt;BR /&gt;Are you implementing &amp;nbsp;&lt;EM&gt;&lt;FONT color="#FF6600"&gt;enableOldS2SProtocol=true&lt;/FONT&gt;&lt;/EM&gt;?&lt;BR /&gt;&lt;BR /&gt;If yes, read below.&lt;/P&gt;&lt;P&gt;Splunk has dropped support for oldest S2S version. However added&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Outputsconf" target="_self"&gt;enableOldS2SProtocol&lt;/A&gt; config to allow forwarder use oldest protocol.&lt;BR /&gt;&lt;BR /&gt;With &lt;EM&gt;&lt;FONT color="#FF6600"&gt;enableOldS2SProtocol=true&lt;/FONT&gt;&lt;/EM&gt;, forwarder is allowed to&amp;nbsp; use oldest protocol (protocol level 0). First ever protocol. You are essentially using almost 20 years old protocol.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;With &lt;EM&gt;&lt;FONT color="#FF6600"&gt;enableOldS2SProtocol=false&lt;/FONT&gt;&lt;/EM&gt;, forwarder is allowed to&amp;nbsp; use minimum protocol level 1 with&amp;nbsp;&lt;FONT color="#FF6600"&gt;negotiateProtocolLevel&lt;/FONT&gt; config.&lt;/P&gt;&lt;P&gt;If&amp;nbsp;&lt;FONT color="#FF6600"&gt;negotiateProtocolLevel&amp;nbsp;&lt;FONT color="#000000"&gt;is not set( by default not set), then forwarder and receiver will be negotiating latest common protocol supported by&amp;nbsp;forwarder and receiver.&lt;BR /&gt;&lt;/FONT&gt;&lt;/FONT&gt;If you are on Splunk 9.2.x receiver and forwarder is 9.0.x and above, then protocol 6 is being used.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;When protocol negotiation happens between fwd and receiver, if the receiver says&amp;nbsp; protocol 0, fwd does not accept that and still use minimum supported protocol 1 unless &lt;FONT color="#FF6600"&gt;enableOldS2SProtocol=true&lt;/FONT&gt; is set on fwd.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;Suggesting&amp;nbsp;&lt;STRONG&gt;&lt;FONT color="#FF6600"&gt;enableOldS2SProtocol=true&lt;/FONT&gt;&lt;/STRONG&gt;&amp;nbsp;on fwd means receiver is only capable of&amp;nbsp;&lt;STRONG&gt;protocol 0 &lt;/STRONG&gt;and forcing fwd to use&amp;nbsp;&lt;FONT color="#FF6600"&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;protocol 0&lt;/STRONG&gt;.&lt;/FONT&gt;&lt;/FONT&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;Suggesting&amp;nbsp;&lt;STRONG&gt;&lt;FONT color="#FF6600"&gt;enableOldS2SProtocol=true&lt;/FONT&gt;&lt;/STRONG&gt;&amp;nbsp;and&amp;nbsp;&lt;FONT color="#FF6600"&gt;negotiateProtocolLevel=0&amp;nbsp;&lt;FONT color="#000000"&gt;on fwd means fwd is forced to use &lt;STRONG&gt;protocol 0 &lt;/STRONG&gt;regardless of receiver's protocol level.&lt;/FONT&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;Protocol levels.&lt;BR /&gt;0: Maximum network traffic over S2S connection.&lt;BR /&gt;1: Network traffic optimization&amp;nbsp;over S2S connection.&lt;BR /&gt;2: Additional network traffic optimization&amp;nbsp;over S2S connection.&lt;BR /&gt;3: Metric support.&lt;BR /&gt;4: Ack support for rawless metric events.&lt;BR /&gt;5: Flag potential dup events.&lt;BR /&gt;6: Flag for cloned metric events so that cloned events exempted from license usage.&lt;BR /&gt;7: SSL certificate requests&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Make an informed decision.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Mar 2025 11:07:02 GMT</pubDate>
    <dc:creator>hrawat</dc:creator>
    <dc:date>2025-03-21T11:07:02Z</dc:date>
    <item>
      <title>Splunk  supported S2S protocols and enableOldS2SProtocol (oldest protocol) explained</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-supported-S2S-protocols-and-enableOldS2SProtocol-oldest/m-p/741714#M10786</link>
      <description>&lt;P&gt;Are you recommending&amp;nbsp;&lt;EM&gt;&lt;FONT color="#FF6600"&gt;enableOldS2SProtocol=true&lt;/FONT&gt;&lt;/EM&gt;?&lt;BR /&gt;Are you implementing &amp;nbsp;&lt;EM&gt;&lt;FONT color="#FF6600"&gt;enableOldS2SProtocol=true&lt;/FONT&gt;&lt;/EM&gt;?&lt;BR /&gt;&lt;BR /&gt;If yes, read below.&lt;/P&gt;&lt;P&gt;Splunk has dropped support for oldest S2S version. However added&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/Outputsconf" target="_self"&gt;enableOldS2SProtocol&lt;/A&gt; config to allow forwarder use oldest protocol.&lt;BR /&gt;&lt;BR /&gt;With &lt;EM&gt;&lt;FONT color="#FF6600"&gt;enableOldS2SProtocol=true&lt;/FONT&gt;&lt;/EM&gt;, forwarder is allowed to&amp;nbsp; use oldest protocol (protocol level 0). First ever protocol. You are essentially using almost 20 years old protocol.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;With &lt;EM&gt;&lt;FONT color="#FF6600"&gt;enableOldS2SProtocol=false&lt;/FONT&gt;&lt;/EM&gt;, forwarder is allowed to&amp;nbsp; use minimum protocol level 1 with&amp;nbsp;&lt;FONT color="#FF6600"&gt;negotiateProtocolLevel&lt;/FONT&gt; config.&lt;/P&gt;&lt;P&gt;If&amp;nbsp;&lt;FONT color="#FF6600"&gt;negotiateProtocolLevel&amp;nbsp;&lt;FONT color="#000000"&gt;is not set( by default not set), then forwarder and receiver will be negotiating latest common protocol supported by&amp;nbsp;forwarder and receiver.&lt;BR /&gt;&lt;/FONT&gt;&lt;/FONT&gt;If you are on Splunk 9.2.x receiver and forwarder is 9.0.x and above, then protocol 6 is being used.&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;When protocol negotiation happens between fwd and receiver, if the receiver says&amp;nbsp; protocol 0, fwd does not accept that and still use minimum supported protocol 1 unless &lt;FONT color="#FF6600"&gt;enableOldS2SProtocol=true&lt;/FONT&gt; is set on fwd.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;Suggesting&amp;nbsp;&lt;STRONG&gt;&lt;FONT color="#FF6600"&gt;enableOldS2SProtocol=true&lt;/FONT&gt;&lt;/STRONG&gt;&amp;nbsp;on fwd means receiver is only capable of&amp;nbsp;&lt;STRONG&gt;protocol 0 &lt;/STRONG&gt;and forcing fwd to use&amp;nbsp;&lt;FONT color="#FF6600"&gt;&lt;FONT color="#000000"&gt;&lt;STRONG&gt;protocol 0&lt;/STRONG&gt;.&lt;/FONT&gt;&lt;/FONT&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;BR /&gt;Suggesting&amp;nbsp;&lt;STRONG&gt;&lt;FONT color="#FF6600"&gt;enableOldS2SProtocol=true&lt;/FONT&gt;&lt;/STRONG&gt;&amp;nbsp;and&amp;nbsp;&lt;FONT color="#FF6600"&gt;negotiateProtocolLevel=0&amp;nbsp;&lt;FONT color="#000000"&gt;on fwd means fwd is forced to use &lt;STRONG&gt;protocol 0 &lt;/STRONG&gt;regardless of receiver's protocol level.&lt;/FONT&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;Protocol levels.&lt;BR /&gt;0: Maximum network traffic over S2S connection.&lt;BR /&gt;1: Network traffic optimization&amp;nbsp;over S2S connection.&lt;BR /&gt;2: Additional network traffic optimization&amp;nbsp;over S2S connection.&lt;BR /&gt;3: Metric support.&lt;BR /&gt;4: Ack support for rawless metric events.&lt;BR /&gt;5: Flag potential dup events.&lt;BR /&gt;6: Flag for cloned metric events so that cloned events exempted from license usage.&lt;BR /&gt;7: SSL certificate requests&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;Make an informed decision.&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2025 11:07:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-supported-S2S-protocols-and-enableOldS2SProtocol-oldest/m-p/741714#M10786</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2025-03-21T11:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk  supported S2S protocols and enableOldS2SProtocol (oldest protocol) explained</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-supported-S2S-protocols-and-enableOldS2SProtocol-oldest/m-p/743999#M10877</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/118813"&gt;@hrawat&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;&lt;BR /&gt;Protocol levels.&lt;BR /&gt;0: Maximum network traffic over S2S connection.&lt;BR /&gt;1: Network traffic optimization&amp;nbsp;over S2S connection.&lt;BR /&gt;2: Additional network traffic optimization&amp;nbsp;over S2S connection.&lt;BR /&gt;3: Metric support.&lt;BR /&gt;4: Ack support for rawless metric events.&lt;BR /&gt;5: Flag potential dup events.&lt;BR /&gt;6: Flag for cloned metric events so that cloned events exempted from license usage.&lt;BR /&gt;7: SSL certificate requests&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;This is the first time I recall seeing any documentation on the protocol levels. Can you elaborate what "7: SSL certificate requests" means?&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 01:27:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-supported-S2S-protocols-and-enableOldS2SProtocol-oldest/m-p/743999#M10877</guid>
      <dc:creator>jstratton</dc:creator>
      <dc:date>2025-04-11T01:27:18Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk  supported S2S protocols and enableOldS2SProtocol (oldest protocol) explained</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-supported-S2S-protocols-and-enableOldS2SProtocol-oldest/m-p/744016#M10878</link>
      <description>&lt;P&gt;SSL cert files are reloaded since these are essentially not part of the outputs.conf.&lt;BR /&gt;However if you changed cert path in outputs.conf, then it was not honored.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 13:25:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-supported-S2S-protocols-and-enableOldS2SProtocol-oldest/m-p/744016#M10878</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2025-04-11T13:25:45Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk  supported S2S protocols and enableOldS2SProtocol (oldest protocol) explained</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-supported-S2S-protocols-and-enableOldS2SProtocol-oldest/m-p/744019#M10879</link>
      <description>&lt;P&gt;&amp;gt;&lt;SPAN&gt;Can you elaborate what "7: SSL certificate requests" means?&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;Means if you have new certificate rotated by receiver then clients will also rotate new certificate. This will help not manually restarting thousands of fwds to reload certificate.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2025 13:28:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Splunk-supported-S2S-protocols-and-enableOldS2SProtocol-oldest/m-p/744019#M10879</guid>
      <dc:creator>hrawat</dc:creator>
      <dc:date>2025-04-11T13:28:18Z</dc:date>
    </item>
  </channel>
</rss>

