Security

Splunk Forwarder Certificate Re-creation.

SandzVG
Explorer

Hello Admins,

related to my earlier question, which went unanswered 😞
http://answers.splunk.com/answers/232151/the-subject-common-name-cn-found-in-the-x509-cert.html

i've deleted the server.pem and have restarted the SplunkForwarder service and it has been re-generated with the same CN = SplunkServerDefaultCert. I would like this to be the Hostname of the server in which it runs instead of the Default.

can you please throw some light on what steps the re-start service would do and how it re-generates the certificate?

Thanks

Venu

1 Solution

starcher
Influencer

You need to make your own certificates with another CA if you want to use custom CN etc information. That is the default Splunk SSL certificate. These slides might help. http://www.georgestarcher.com/wp-content/uploads/2014/11/Nashville-UG-Splunk-SSL-Presentation.pdf

View solution in original post

starcher
Influencer

You need to make your own certificates with another CA if you want to use custom CN etc information. That is the default Splunk SSL certificate. These slides might help. http://www.georgestarcher.com/wp-content/uploads/2014/11/Nashville-UG-Splunk-SSL-Presentation.pdf

Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...