Getting Data In

Splunk HF to send both SSL and Not SSL to Indexer Cluster

brewmonk57
New Member

Hi Splunkers,

I have some HF configured to send data over SSL to one indexer;

As I am about to configure a second indexer, I was wondering if it is possible to load-balance data from HF to:

  • IDX1 over SSL
  • IDX2 without SSL

And have outputs.conf configured such as:

[tcpout]
defaultGroup = default-autolb-group

[tcpout:default-autolb-group]

server = idx1:1234,idx2:5678

 

where 1234 is the SSL port, and 5678 the standard one, without SSL.

and on indexer side, we would have for inputs.conf

IDX1

[splunktcp-ssl://1234]
connection_host = dns

IDX2

[splunktcp://5678]
connection_host = dns

 

Do you think this could work?

Thanks !

Labels (2)
0 Karma

astackpole
Path Finder

If you're required to ingest multiple data sources where some are encrypted and some are not, then you can send them to the Heavy Forwarder in their current state and then forward to the indexer cluster via SSL certificates only from the Heavy Forwarder to the Indexer Cluster. This will allow SSl and non-SSL transactions from the data sources to the Heavy Forwarder.

Not 100% sure if this is what you're looking for but this is the only method I would recommend involving SSL and non-SSL data sources. As Rich said, all the indexers should have the same configuration for things to run properly.

---
If this reply helps you, an upvote would be appreciated.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

First, why would you want to protect communications to one indexer, but not the other one?  The same data is going to both places so if it's worth protecting on one path it should be worth protecting on all paths.

Second, indexers in a cluster should have the same configuration.  Put that configuration on the CM and push it to all indexers.  To do otherwise is to invite trouble later.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...

IM Landing Page Filter - Now Available

We’ve added the capability for you to filter across the summary details on the main Infrastructure Monitoring ...

Dynamic Links from Alerts to IM Navigators - New in Observability Cloud

Splunk continues to improve the troubleshooting experience in Observability Cloud with this latest enhancement ...