Indexer/forwarder SSL communication / sslVerifyServerCert question


Hello, is it possible that Splunkforwarder still works if the cacert.pem on the indexer is expired and from different certificate authority? We have sslVerifyServerCert = false set on the fwd.


0 Karma

Path Finder

it is additional step for authenticating your splunk indexers. For example- If it FALSE, setup an indexer, add and define common certificate and configure to forward the event, it will start ingesting. In this case, certificates, verify, whether it is forwarding events/logs to correct indexers only, but based on certificates

You need to have two more configs need to be added in case, you want it to work,

output.conf, (splunk forwarder - DS client)

between server to server
sslCommonNameList = splunk.servers.names.with.comma.for.all.making.communication,,

Always configure these config in last, as any communication break, can be rolled back, as this would be only check.

0 Karma


Yeah that should be fine as far as I know.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!