Getting Data In

Does Universal Forwarded supports Server Name Indication (SNI)?

tihomirstoyanov
New Member

Hi there folks,

I would like to ask if Universal Forwarder can support Server Name Indication (SNI)? That is extension of TLS protocol which can be used by nginx to deploy SNI-based-routing from UF`s to multiple hosts.

INFO:
- We have many clients with on-premise machines/laptops with Universal Forwarders sending traffic to our AWS Splunk Instances (Indexers). Our AWS Instances doesnt have public IPv4 addresses and we would like to deploy single point of contact (nginx) with public IPv4 address for all TCP UFs traffic which then differentiate by destination.

UF -> nginx with public IPv4 (SNI based-routing) -> AWS Target Indexer

Pre-requisites:
We need UF with enabled SSL - this is completed.
We need UF with enabled SNI (Its needed to differentiate destination hosts)

e.g. UF`s will send traffic to:
client1.mydomain.com
client2.mydomain.com

Nginx will then route the traffic to destination.

Have someone tried similar approach before? Also if you could give other suggestion for our solution will be much appreciated!

Thank you.

Kind Regards,
Tihomir Stoyanov

0 Karma

tihomirvstoyano
Engager

Hello,

Got an update from our seniors --> Universal Forwarder doesn`t support SNI at the moment.

Thanks,
Tihomir Stoyanov

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...