Monitoring Splunk

How to complete Certs definitions in config?

PickleRick
SplunkTrust
SplunkTrust

I'm trying to do my own "poor man's certificate check" 😉

Ideally I'd like to pick up from the config (btool output) the paths to certs so I could check them with openssl CLI tool. I don't want to do any python modular input stuff for that since I want it to run as a simple script on any machine with UF. The question therefore is where should I get my certs from.

serverCert, RootCA, clientCert, sslRootCAPath entries in inputs.conf, outputs.conf, servers.conf, deploymentclients.conf (of course they don't have to be defined in each file). For now I assume the "new" configuration format with a single pem.

Any files that I forgot? Any more entries I missed? 🙂

 

Labels (1)
Tags (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

At least authentication.conf and web.conf have some cert definitions over those which you already listed.

In some weird situation also /opt/splunk/splunk/etc/openldap/ldap.conf can have uncommented entries for those?

r. Ismo

PickleRick
SplunkTrust
SplunkTrust

web.conf - sure; don't know how I omitted it.

authentication/ldap - you're right. I forgot about external authentication. I mostly use local accounts but of course makes sense.

0 Karma
Get Updates on the Splunk Community!

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...