Splunk Enterprise

authentication mechanism between deployment server and deployment clients

naagaraj
Engager

Hi All,

I have done a deployment server setup with over 20 machines. The deployment setup is working fine.

The security team has come up with a question regarding the communication between the splunk deployment server and the forwarders.

They wanted to know whether there is any API key through which authentication happens when the forwarders contacts the deployment server.

Is there any other authentication mechanism which takes place in this communication.

Any information would be helpful.

 

Thanks

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

By default, there is no authentication between the deployment server and its clients.  Connections are accepted from forwarders based on the whitelist and blacklist settings. 

You can add security by using certificates.  See https://docs.splunk.com/Documentation/Splunk/8.0.4/Security/Securingyourdeploymentserverandclients

---
If this reply helps you, Karma would be appreciated.

naagaraj
Engager

Hi Richgalloway,

 

Thanks for your reply. 

Do u also know if the certificates can also be pushed from deployment server to the clients similar to configurations.

Thanks

0 Karma

JBsplunkIT
Engager

Yes you can push out certificates just remember the password will need to be pushed along with it and it will be hashed by each machine it gets installed on

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...