- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We need to connect a FortiWeb Cloud with a Splunk Heavy Forwarder.
It is over internet so SSL must be used.
We are receiving the test event correctly using TCP (without SSL)
But it is not being decrypted with SSL
Reviewing the documentation, we do not undesrtand how to configure the ssl-tcp input, and what certificates should be configured in FortiWeb.
We have seen some solutions centered in SSL between Splunk components, but none of them explain what certificates should be configured on the source.
Does anyone know how to make this work? With FortiWeb or any other third party input
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We succesfully configured FortiWeb SaaS -> Splunk SSL syslog via inputs.conf
[tcp-ssl:6514]
index = <index>
sourcetype = fwbcld_log
disabled = 0
[SSL]
requireClientCert = false
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We succesfully configured FortiWeb SaaS -> Splunk SSL syslog via inputs.conf
[tcp-ssl:6514]
index = <index>
sourcetype = fwbcld_log
disabled = 0
[SSL]
requireClientCert = false
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believe the link below will assist you with your question.
https://community.splunk.com/t5/Security/TCP-Data-Input-and-SSL/m-p/483077
