Getting Data In

Validate third party ssl splunk2splunk communication

vasanthmss
Motivator

Hi splunkers

I've configured 3rd party ssl between indexer and h.f. indexer 9997 open for tcp, 9996 for ssl. I've configured output confs for 9996 and sent the data . I could not see any internal logs as like wiki(older version). There is no updated document version for Splunk 2 Splunk third party ssl validation. I'm using 6.2.1 build for indexer and h.f.

Any idea how to validate that the data sent from h.f is encrypted?

Thanks
V

V
1 Solution

jworthington_sp
Splunk Employee
Splunk Employee

I'm not clear on your exact configuration, but it sounds like you are doing some indexing on the heavy forwarder and want to know how to validate the forwarder to Splunk connection? If that is the case, this topic might help: http://docs.splunk.com/Documentation/Splunk/latest/Security/Validateyourconfiguration

View solution in original post

jworthington_sp
Splunk Employee
Splunk Employee

I'm not clear on your exact configuration, but it sounds like you are doing some indexing on the heavy forwarder and want to know how to validate the forwarder to Splunk connection? If that is the case, this topic might help: http://docs.splunk.com/Documentation/Splunk/latest/Security/Validateyourconfiguration

Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...