I am planning to use a bunch of universal forwarders, sending logs to a group of heavy forwarders. How do I enable SSL and Authentication between universal forwarder and heavy forwarder?
Hi @jaykumar_jnpr,
Have a look at Splunk Document https://docs.splunk.com/Documentation/Splunk/7.2.1/Security/Aboutsecuringdatafromforwarders and if you will face any issue or you have any query then feel free to ask.
Also look at Splunk Conf Slides for SSL implementation https://conf.splunk.com/session/2015/conf2015_DWaddle_DefensePointSecurity_deploying_SplunkSSLBestPr...