Splunk Enterprise

Enforcing TLS v 1.3 on AWS

lwray21
Engager

Is there a way to enforce/enable TLS 1.3 on Splunk HEC traffic?

I am looking to enforce TLS 1.3 on Splunk Enterprise deployed in AWS. I am currently using a classic AWS load balancer in front of my index cluster as the entry point for all logging traffic. When attempting to make the change over to an application load balancer with a TLS 1.3 policy attached the logs fail to send to the splunk indexers.

Labels (1)
0 Karma

thahir
Contributor

@lwray21 You cannot currently enforce TLS 1.3 for Splunk HEC traffic; Splunk only supports up to TLS 1.2 for inbound HEC connections, so an ALB with TLS 1.3-only policy will not work.

0 Karma

PickleRick
SplunkTrust
SplunkTrust

As of the 10.0 version Splunk does not yet support TLS 1.3. Judging from some posts on this forum the TLS1.3 support is in the works but no specific schedule has been given yet.

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...