Splunk Enterprise

What is the best method for Indexer not to accept traffics from unknown forwarder?

ducthinhle
Engager

Hello All,

Other than using Authentication between forwarders and Indexer,
I am just wondering if there is a simple way to indicate to an
Indexer to ONLY accept connection (forwarding traffics) from
a set of known forwarders. Thanks.

Regards
DL

Tags (1)

gkanapathy
Splunk Employee
Splunk Employee

Using SSL authentication where the forwarder must present a certficate signed by the appropriate CA is probably the most secure way. You could also configure a firewall or iptables on the Splunk indexer to allow only traffic to the indexer inbound ports from the IP addresses of the known forwarders. That's perhaps a little less overhead to set up.

Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...