Can we configure the forwarders to use SFTP for transferring the files? If not is there any way to encrypt data by Universal Forwarder (UF)? Does UF support SSL?
The UF supports SSL. You cannot use sftp. Here is the explanation in the documentation:
Configure Splunk forwarding to use your own certificates in the Securing Splunk Enterprise manual.
FYI, I found this by using Google and searching for "Splunk forwarder SSL"
There are also a bunch of questions - and answers - on this site, which the Google results also show.
Good luck!
The UF supports SSL. You cannot use sftp. Here is the explanation in the documentation:
Configure Splunk forwarding to use your own certificates in the Securing Splunk Enterprise manual.
FYI, I found this by using Google and searching for "Splunk forwarder SSL"
There are also a bunch of questions - and answers - on this site, which the Google results also show.
Good luck!