Getting Data In

How to establish secure connection between Universal Forwarders and Heavy Forwarders in a distributed environment?

hartley
Explorer

Hi,

Good day!

We have distributed Splunk Enterprise setup, we are trying to establish secure SSL communication between UF-> HF-> Indexer.
We do have certificates configured for Search heads, Indexers and Heavy Forwarders. We have also opened required receiving ports on both Indexer and HF.
On the other hand, we have around 200 UF's, can someone please tell me, if we need to generate 200 client certificates or we can use general certificate which we can deploy on all 200 UF's for establishing communication between UF and HF.

Thanks,
D Vijaya

0 Karma
1 Solution

nickhills
Ultra Champion

Take a look at this excellent presentation from .conf15 which walks you through creating and applying certificates across all of your Splunk infrastructure:

Slide 18+ covers Forwarders.
https://conf.splunk.com/session/2015/conf2015_DWaddle_DefensePointSecurity_deploying_SplunkSSLBestPr...

You can create one certificate which all your UFs will use, you don't need 200 certs!

If my comment helps, please give it a thumbs up!

View solution in original post

0 Karma

hartley
Explorer

Thanks guys.. your response would help 🙂

0 Karma

nickhills
Ultra Champion

Take a look at this excellent presentation from .conf15 which walks you through creating and applying certificates across all of your Splunk infrastructure:

Slide 18+ covers Forwarders.
https://conf.splunk.com/session/2015/conf2015_DWaddle_DefensePointSecurity_deploying_SplunkSSLBestPr...

You can create one certificate which all your UFs will use, you don't need 200 certs!

If my comment helps, please give it a thumbs up!
0 Karma

harsmarvania57
SplunkTrust
SplunkTrust

Hi,

You can use common certificate on all 200 UF which will connect with HF/IDX.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Updates (ESCU) - New Releases

In the last month, the Splunk Threat Research Team (STRT) has had 3 releases of new content via the Enterprise ...

Thought Leaders are Validating Your Hard Work and Training Rigor

As a Splunk enthusiast and member of the Splunk Community, you are one of thousands who recognize the value of ...

.conf23 Registration is Now Open!

Time to toss the .conf-etti 🎉 —  .conf23 registration is open!   Join us in Las Vegas July 17-20 for ...