Splunk Enterprise Security

Check secure communication establish between search head and indexer

arun_kant_sharm
Path Finder

Hi Experts,

I am new in Splunk, especially in a Splunk distributed environment creation.
For enable SSL on splunkWeb , I modified the local copy of web.conf file ( https://docs.splunk.com/Documentation/Splunk/7.3.1/Admin/Webconf ), and its perfectly working fine.

But to establish secure communication between in Search Head and Indexer , I modified Input.conf file

https://docs.splunk.com/Documentation/Splunk/7.3.1/Security/ConfigureSplunkforwardingtousethedefault...

Is there any way to verify the communication between Indexers and search heads are secure?
(Using any CLI command or any other way) . I want to verify it before installing any splunk app.

0 Karma

lakshman239
Influencer

The communication between SH and Indexers is SSL/encrypted by default. You don't need to do anything unless you want to change the default certs. https://docs.splunk.com/Documentation/Splunk/7.3.1/Security/Securingdistributedsearchheadsandpeers

0 Karma
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.


Introducing Unified TDIR with the New Enterprise Security 8.2

Read the blog
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...