Security

HEC Invalid SSL Certificate

aaptiv_engineer
New Member

Hi,
I'm using Splunk Cloud with an HEC configured via Settings --> Data Inputs --> HTTP Event Collector
I can submit an event via curl, but when attempting to send via AWS Firehose, it fails with an SSL error.
It appears that the SSL cert installed on the HEC is a self-signed certificate.

How can I get the Splunk Cloud HEC configured with a valid cert?

Tags (3)
0 Karma

Albakercss
New Member

Hi,
I would recomend you use a Heavy Forwarder as your HEC endpoint, then send your data on to the Splunk Cloud via normal forwarder method.
A ticket would need to be raised with the Splunk Cloud team, to get the Certificate fixed.
If you do this via a heavy forwarder, look through this section of the manual "AboutsecuringyourSplunkconfigurationwithSSL"

If you would like a good presentation to talk you through setting up, this is a simple guide around the SSL certificate. Best Practices Configuration for Splunk SSL

https://docs.splunk.com/Documentation/Splunk/7.1.2/Security/AboutsecuringyourSplunkconfigurationwith...
https://conf.splunk.com/session/2015/conf2015_DWaddle_DefensePointSecurity_deploying_SplunkSSLBestPr...

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...