Is there a way to enforce/enable TLS 1.3 on Splunk HEC traffic?
I am looking to enforce TLS 1.3 on Splunk Enterprise deployed in AWS. I am currently using a classic AWS load balancer in front of my index cluster as the entry point for all logging traffic. When attempting to make the change over to an application load balancer with a TLS 1.3 policy attached the logs fail to send to the splunk indexers.
@lwray21 You cannot currently enforce TLS 1.3 for Splunk HEC traffic; Splunk only supports up to TLS 1.2 for inbound HEC connections, so an ALB with TLS 1.3-only policy will not work.
As of the 10.0 version Splunk does not yet support TLS 1.3. Judging from some posts on this forum the TLS1.3 support is in the works but no specific schedule has been given yet.