Security

SSL Communication between Splunk Indexers and UF/HF

sankaraniyan1
Explorer

Hi All,

   I have a weird requirement here but maybe some expert help might be showered .

I have a set of 800+ agents distributed across 3 Data center ( 1 primary DC and 2 secondary DC) and  client expects us to use SSL communication between the Datacenter. I use a Heavy Forwarder ( HF) at those 2 secondary DC to do some custom monitoring .

I have the solution finalized, with Indexer cluster and SH  to be at Primary DC.  I am planning to use a single indexer cluster to receive data from all forwarders. Now I am looking at following query i have.

1) Can i have my Universal forwarders in the primary DC talk without SSL certificates, while communication from UF agents in other DC is with SSL ?

2) Can i have the UF's in secondary DC talk to the HF in secondary DC without SSL and Data from HF's forwarder to Indexer over SSL.

  Basically can I configure SSL and non SSL communication in a single set of Indexer cluster ?

 

SKR..

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...