Splunk Enterprise

authentication mechanism between deployment server and deployment clients

naagaraj
Engager

Hi All,

I have done a deployment server setup with over 20 machines. The deployment setup is working fine.

The security team has come up with a question regarding the communication between the splunk deployment server and the forwarders.

They wanted to know whether there is any API key through which authentication happens when the forwarders contacts the deployment server.

Is there any other authentication mechanism which takes place in this communication.

Any information would be helpful.

 

Thanks

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

By default, there is no authentication between the deployment server and its clients.  Connections are accepted from forwarders based on the whitelist and blacklist settings. 

You can add security by using certificates.  See https://docs.splunk.com/Documentation/Splunk/8.0.4/Security/Securingyourdeploymentserverandclients

---
If this reply helps you, Karma would be appreciated.

naagaraj
Engager

Hi Richgalloway,

 

Thanks for your reply. 

Do u also know if the certificates can also be pushed from deployment server to the clients similar to configurations.

Thanks

0 Karma

JBsplunkIT
Engager

Yes you can push out certificates just remember the password will need to be pushed along with it and it will be hashed by each machine it gets installed on

Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...