Hi All,
I have done a deployment server setup with over 20 machines. The deployment setup is working fine.
The security team has come up with a question regarding the communication between the splunk deployment server and the forwarders.
They wanted to know whether there is any API key through which authentication happens when the forwarders contacts the deployment server.
Is there any other authentication mechanism which takes place in this communication.
Any information would be helpful.
Thanks
By default, there is no authentication between the deployment server and its clients. Connections are accepted from forwarders based on the whitelist and blacklist settings.
You can add security by using certificates. See https://docs.splunk.com/Documentation/Splunk/8.0.4/Security/Securingyourdeploymentserverandclients
Hi Richgalloway,
Thanks for your reply.
Do u also know if the certificates can also be pushed from deployment server to the clients similar to configurations.
Thanks
Yes you can push out certificates just remember the password will need to be pushed along with it and it will be hashed by each machine it gets installed on