Getting Data In

Does Splunk support two-way SSL between the Universal Forwarder TCP port and external application?

ankithreddy777
Contributor

Does Splunk's Universal Forwarder supports SSL for TCP inputs (i.e It is receiving data from external application)? Does Splunk supports 2 way SSL between them?

0 Karma

koshyk
Super Champion
  1. We use TLS1.2 for Splunk UF to Indexers using certificates. So answer for 1st question is YES
  2. I'm not sure what you mean as 2 way SSL between them? You mean from Deployment-server to UF? (Yes in that case). Indexers don't need to communicate back to UF, so it is one way traffic only.
0 Karma

ankithreddy777
Contributor

Hi Koshyk,
I mean Does the traffic between external system (say Cloud foundry) to tcp port of Splunk UF has SSL b/w them?

Splunk UF TCP port xxx is receiving data from external source and forwarding it to Splunk Indexers.

Coming to splunk UF and indexers. In case when indexers send acknowledgement back to forwarders, is it not secured by SSL?

Thank you

0 Karma

koshyk
Super Champion

if the connection is between Cloud-foundry and UF, you can enable SSL/TLS if you enable certificates accordingly.

if its between UF & Indexers/HF/UF => the network connection is opened by UF and is Secured. So the acknowledgement is using the same connection and hence is secured.

0 Karma

ankithreddy777
Contributor

Hi Koshyk,
yes, the connection is between Cloud-foundry and UF, How to enable certificates for UF. Splunk docs gave information about how to configure inputs.conf for indexers and outputs.conf for UF for enabling SSL in case of connection between UF and Indexers. But how to configure splunk conf in my case?

thankyou

0 Karma

koshyk
Super Champion

The documents provide step by step method. Please use Link : http://docs.splunk.com/Documentation/Splunk/6.5.3/Security/ConfigureSplunkforwardingtousesignedcerti...

(Please mark answer if you are satisfied. cheers)

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2026-2027 SplunkTrust is officially open. If ...