Getting Data In

Why don't UFs parse data when docs say splunktcp-ssl is only for "parsed" data to indexers?

Path Finder

According to the Splunk documentation on the attribute [splunktcp-ssl:<port>] it states that:

 * Use this stanza type if you are receiving encrypted, parsed data from a forwarder."

UFs cook, but do not 'parse' the data.  Thus, is this effective to send encrypted data from the UF to indexers?

Labels (1)
0 Karma


I think this may be a place where the documentation needs improvement.  Splunk Cloud uses SSL exclusively with UFs so you should be able to, also.

If this reply helps you, Karma would be appreciated.

Splunk Employee
Splunk Employee

Please submit feedback using the form at the bottom of the documentation page you are looking at. That creates a ticket for the doc team and we will follow up, thank you!

0 Karma
Get Updates on the Splunk Community!

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out &gt;&gt; As our brave ...

Customer Experience | Call for Stories: Your 2023 Journey with Splunk!

Share your Splunk journey: Splunk is committed to supporting our customers toward success. As the year draws ...

Infographic provides the TL;DR for the 2023 Splunk Career Impact Report

We’ve been shouting it from the rooftops! The findings from the 2023 Splunk Career Impact Report showing that ...