Getting Data In

Working on Securing Data with SSL between Heavy Forwarder and Universal Forwarder using default certificates

YusufK
Loves-to-Learn Lots

Hi, I am having trouble attempting to get a deployment server and a deployment client to communicate and then access data through the Splunk search using SSL with Splunk default certificates. What steps would I have to go through to achieve this? So I am trying to get my deployment server A with default certs cacert.pem and server.pem in /etc/auth to communicate with Server B which also has the same default certs in /etc/auth. 

I have defined the Deployment Server server.conf and inputs.conf as shown:

 

[sslConfig]

enableSplunkdSSL = false
useClientSSLCompression = true
serverCert = /xxxxx/splunk/etc/auth/server.pem
sslPassword = password
sslRootCAPath = /xxxx/splunk/etc/auth/cacert.pem
certCreateScript = genMyServerCert.sh

 

inputs.conf

 

[SSL]
serverCert = /xxxx/splunk/etc/auth/server.pem
password = password
rootCA = /xxxx/splunk/etc/auth/cacert.pem
requireClientCert = false
sslVersions = tls,-ssl3

 

On my  Server B or Deployment Client, my server.conf is defined as

[sslConfig]

enableSplunkdSSL = true
[default]
useClientSSLCompression = true
serverCert = /xxxx/splunkforwarder/etc/auth/server.pem
sslPassword = password
sslRootCAPath = /xxxx/splunkforwarder/etc/auth/cacert.pem
certCreateScript = genMyServerCert.sh

What .conf files do I need to edit and what stanzas will I need to define on the Deployment Client(server B) for them to communicate and eventually I can search Server B on my search head? Sorry if this is unclear but I will be answering any questions on what I am asking.

Thank you.

Labels (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi @YusufK the question heading says about heavy forwarder.. do you want SSL between

UF--->HF--->indexer 

OR

Deployment Server <---> UF

(for this, hope you referred the documentation https://docs.splunk.com/Documentation/Splunk/8.0.6/Security/Securingyourdeploymentserverandclients )

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

YusufK
Loves-to-Learn Lots

Hi I am looking for 

 

Deployment Server <---> UF

 

For example, Server A is my Deployment Server AND Heavy Forwarder. Server B is my Deployment Client. I would like them to communicate with the default cert, and I would like searchable results in the search bar for Server B.

 

Thank you.

0 Karma
Get Updates on the Splunk Community!

Fall Into Learning with New Splunk Education Courses

Every month, Splunk Education releases new courses to help you branch out, strengthen your data science roots, ...

Super Optimize your Splunk Stats Searches: Unlocking the Power of tstats, TERM, and ...

By Martin Hettervik, Senior Consultant and Team Leader at Accelerate at Iver, Splunk MVPThe stats command is ...

How Splunk Observability Cloud Prevented a Major Payment Crisis in Minutes

Your bank's payment processing system is humming along during a busy afternoon, handling millions in hourly ...