Security

HEC Invalid SSL Certificate

aaptiv_engineer
New Member

Hi,
I'm using Splunk Cloud with an HEC configured via Settings --> Data Inputs --> HTTP Event Collector
I can submit an event via curl, but when attempting to send via AWS Firehose, it fails with an SSL error.
It appears that the SSL cert installed on the HEC is a self-signed certificate.

How can I get the Splunk Cloud HEC configured with a valid cert?

Tags (3)
0 Karma

Albakercss
New Member

Hi,
I would recomend you use a Heavy Forwarder as your HEC endpoint, then send your data on to the Splunk Cloud via normal forwarder method.
A ticket would need to be raised with the Splunk Cloud team, to get the Certificate fixed.
If you do this via a heavy forwarder, look through this section of the manual "AboutsecuringyourSplunkconfigurationwithSSL"

If you would like a good presentation to talk you through setting up, this is a simple guide around the SSL certificate. Best Practices Configuration for Splunk SSL

https://docs.splunk.com/Documentation/Splunk/7.1.2/Security/AboutsecuringyourSplunkconfigurationwith...
https://conf.splunk.com/session/2015/conf2015_DWaddle_DefensePointSecurity_deploying_SplunkSSLBestPr...

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...