Security

SSL/TLS on a TCP data input?

dholmes007
New Member

I need to setup a TCP data input and I need to ensure that it is SSL/TLS.

I understand that I can add a stanza to an inputs.conf file as referenced in this post:
https://answers.splunk.com/answers/684045/how-to-enable-tcp-data-input-with-ssl.html?utm_source=type...

My question is - which inputs.conf file? The data is coming in to my Search Head server and there are a bunch of apps installed there, each with their own inputs.conf file. Which one controls the TCP Data Inputs?

Thanks.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Any app can contain inputs.conf and set TCP attributes. I recommend creating a custom app (org_tcpinputs) for the settings. Before restarting Splunk to apply the changes, run btool to verify the settings are as you expect. That's to avoid conflicts with another app.

---
If this reply helps you, Karma would be appreciated.
0 Karma

dholmes007
New Member

Is there a default place where the TCP Input would look for its settings once I have created it?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Splunk looks in all inputs.conf files and merges what it finds based on the precedence order described at https://docs.splunk.com/Documentation/Splunk/8.0.2/Admin/Wheretofindtheconfigurationfiles

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...