Getting Data In

Decode Logs coming from Syslog (SSL)

elli_i
Engager

Hi,
i am trying to send encrypted logs from Syslog to Splunk. To decrypt them i changed the splunk/etc/system/local/inputs.conf file like so:
[tcp-ssl:5140]
[SSL]
serverCert = path.pem
sslPassword = password

I already get the encrypted Logs but the decryption doesnt work.
Can you help me?

0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

The tcp-ssl stanza just enables ssl on the connection from the syslog server to the splunk server. It's not going to handle any decryption of the underlying data.

View solution in original post

crendon_splunk
Splunk Employee
Splunk Employee

I know has been long time, were you able to decryp the logs at the end?

0 Karma

jkat54
SplunkTrust
SplunkTrust

The tcp-ssl stanza just enables ssl on the connection from the syslog server to the splunk server. It's not going to handle any decryption of the underlying data.

elli_i
Engager

Okay, thanks! And what handles the decryption? I thought by sharing the certificate, with the ssl stanza, decryption is enabled. Or do i have to add a personal script? If so, is there a possibility, to just point splunk to the script, and splunk handles it?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Splunk wont be able to decrypt this. You're going to want to use rsyslog/syslog-ng to do this, and after the files are decrypted and written to disk, use the UF to read the files.

saravanan90
Contributor

Hi @esix_splunk

Is the above state still true with newer version of Splunk. Can Splunk decrypt the encrypted data coming from external?

0 Karma

esix_splunk
Splunk Employee
Splunk Employee

Same still holds true, you cannot send SSL traffic to a Splunk-SSLTCP input and hope Splunk can decrypt it.

Splunk TCP/SSL is for Splunk2Splunk(S2S) over SSL.

 

 

saravanan90
Contributor

Thanks a lot for your quick help @esix_splunk.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...