Getting Data In

Validate third party ssl splunk2splunk communication

vasanthmss
Motivator

Hi splunkers

I've configured 3rd party ssl between indexer and h.f. indexer 9997 open for tcp, 9996 for ssl. I've configured output confs for 9996 and sent the data . I could not see any internal logs as like wiki(older version). There is no updated document version for Splunk 2 Splunk third party ssl validation. I'm using 6.2.1 build for indexer and h.f.

Any idea how to validate that the data sent from h.f is encrypted?

Thanks
V

V
1 Solution

jworthington_sp
Splunk Employee
Splunk Employee

I'm not clear on your exact configuration, but it sounds like you are doing some indexing on the heavy forwarder and want to know how to validate the forwarder to Splunk connection? If that is the case, this topic might help: http://docs.splunk.com/Documentation/Splunk/latest/Security/Validateyourconfiguration

View solution in original post

jworthington_sp
Splunk Employee
Splunk Employee

I'm not clear on your exact configuration, but it sounds like you are doing some indexing on the heavy forwarder and want to know how to validate the forwarder to Splunk connection? If that is the case, this topic might help: http://docs.splunk.com/Documentation/Splunk/latest/Security/Validateyourconfiguration

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk, and empower your SOC to reach new heights! Duration: 1 hour  Prepare to ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...