Security
Highlighted

SSL/TLS on a TCP data input?

New Member

I need to setup a TCP data input and I need to ensure that it is SSL/TLS.

I understand that I can add a stanza to an inputs.conf file as referenced in this post:
https://answers.splunk.com/answers/684045/how-to-enable-tcp-data-input-with-ssl.html?utm_source=type...

My question is - which inputs.conf file? The data is coming in to my Search Head server and there are a bunch of apps installed there, each with their own inputs.conf file. Which one controls the TCP Data Inputs?

Thanks.

Labels (1)
0 Karma
Highlighted

Re: SSL/TLS on a TCP data input?

SplunkTrust
SplunkTrust

Any app can contain inputs.conf and set TCP attributes. I recommend creating a custom app (org_tcpinputs) for the settings. Before restarting Splunk to apply the changes, run btool to verify the settings are as you expect. That's to avoid conflicts with another app.

---
If this reply helps you, an upvote would be appreciated.
0 Karma
Highlighted

Re: SSL/TLS on a TCP data input?

New Member

Is there a default place where the TCP Input would look for its settings once I have created it?

0 Karma
Highlighted

Re: SSL/TLS on a TCP data input?

SplunkTrust
SplunkTrust

Splunk looks in all inputs.conf files and merges what it finds based on the precedence order described at https://docs.splunk.com/Documentation/Splunk/8.0.2/Admin/Wheretofindtheconfigurationfiles

---
If this reply helps you, an upvote would be appreciated.
0 Karma