All Apps and Add-ons

SSL comms for instrumenting JVM in the cloud

Skins
Path Finder

How best could this agent be used to instrument a JVM in the cloud ? (AWS) - how could we encrypt the data streamed to an on-prem instance of Splunk ?

via HEC ? we also intend to deploy a UF in the env to collect os (linux metrics etc) can you send the instrumented data to the UF then send that back to the on-prem instance ?

gratzi

0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

Re: the JVM Agent...the example configuration file that ships with the agent shows how to use HEC as the transport

alt text

Re: forwarding options from a UF , outputs.conf reference is your friend 🙂 So you could forward cooked or uncooked data over TCP back to your on-premise indexers (firewalls permitting of course).

View solution in original post

0 Karma

Damien_Dallimor
Ultra Champion

Re: the JVM Agent...the example configuration file that ships with the agent shows how to use HEC as the transport

alt text

Re: forwarding options from a UF , outputs.conf reference is your friend 🙂 So you could forward cooked or uncooked data over TCP back to your on-premise indexers (firewalls permitting of course).

0 Karma

Skins
Path Finder

Thanks Damien - as both provide a solution - which would you use as a preference?

i would go with sending to the UF > index tier as that would require less config, a single data channel, less FW config?

would you concur?

0 Karma

Damien_Dallimor
Ultra Champion

I concur , simplest and least moving parts is always best.

0 Karma
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...