Splunk Enterprise

authentication mechanism between deployment server and deployment clients

naagaraj
Engager

Hi All,

I have done a deployment server setup with over 20 machines. The deployment setup is working fine.

The security team has come up with a question regarding the communication between the splunk deployment server and the forwarders.

They wanted to know whether there is any API key through which authentication happens when the forwarders contacts the deployment server.

Is there any other authentication mechanism which takes place in this communication.

Any information would be helpful.

 

Thanks

Labels (2)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

By default, there is no authentication between the deployment server and its clients.  Connections are accepted from forwarders based on the whitelist and blacklist settings. 

You can add security by using certificates.  See https://docs.splunk.com/Documentation/Splunk/8.0.4/Security/Securingyourdeploymentserverandclients

---
If this reply helps you, Karma would be appreciated.

naagaraj
Engager

Hi Richgalloway,

 

Thanks for your reply. 

Do u also know if the certificates can also be pushed from deployment server to the clients similar to configurations.

Thanks

0 Karma

JBsplunkIT
Engager

Yes you can push out certificates just remember the password will need to be pushed along with it and it will be hashed by each machine it gets installed on

Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...