Security

Is mgmtHostPort secure?

chengka
Explorer

Hello,
As most large companies do these days, I've been placed on a naughty list for my lab instance of Splunk, running on winServer. I've tracked it down to the mgmtHostPort.

How do I secure that port to use SSL/TLS?

FYI, my web interface is secured and using port 8000, it's this darn internal mgmt port.

Per the doc, I disable it via service.conf, Splunk basically is not usable for searching.

Tags (3)
0 Karma

twinspop
Influencer

By default the management port uses self-signed certs, but it absolutely is SSL (TLS) enabled. If you'd like to secure it with properly signed, or locally signed by your company's CA, there are lots of docs out there. This was a great presentation by splunk legend Dwaddle a few years back.

https://conf.splunk.com/session/2015/conf2015_DWaddle_DefensePointSecurity_deploying_SplunkSSLBestPr...

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...