Splunk Enterprise

What is the best method for Indexer not to accept traffics from unknown forwarder?

ducthinhle
Engager

Hello All,

Other than using Authentication between forwarders and Indexer,
I am just wondering if there is a simple way to indicate to an
Indexer to ONLY accept connection (forwarding traffics) from
a set of known forwarders. Thanks.

Regards
DL

Tags (1)

gkanapathy
Splunk Employee
Splunk Employee

Using SSL authentication where the forwarder must present a certficate signed by the appropriate CA is probably the most secure way. You could also configure a firewall or iptables on the Splunk indexer to allow only traffic to the indexer inbound ports from the IP addresses of the known forwarders. That's perhaps a little less overhead to set up.

Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...