Splunk Enterprise Security

Check secure communication establish between search head and indexer

arun_kant_sharm
Path Finder

Hi Experts,

I am new in Splunk, especially in a Splunk distributed environment creation.
For enable SSL on splunkWeb , I modified the local copy of web.conf file ( https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/Webconf ), and its perfectly working fine.

But to establish secure communication between in Search Head and Indexer , I modified Input.conf file

https://docs.splunk.com/Documentation/Splunk/7.3.1/Security/ConfigureSplunkforwardingtousethedefault...

Is there any way to verify the communication between Indexers and search heads are secure?
(Using any CLI command or any other way) . I want to verify it before installing any splunk app.

0 Karma

lakshman239
Influencer

The communication between SH and Indexers is SSL/encrypted by default. You don't need to do anything unless you want to change the default certs. https://docs.splunk.com/Documentation/Splunk/7.3.1/Security/Securingdistributedsearchheadsandpeers

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...