QuestionQ166

Forwarder and Deployment Best Practices

A customer operates a Splunk Enterprise deployment and needs to collect data from universal forwarders. What is the best action to secure log traffic?

  • A Create signed SSL certificates and use them to encrypt data between the search heads and indexers.
  • B Use the Splunk provided SSL certificates to encrypt data between the forwarders and indexers.
  • C Ensure all forwarded traffic is routed through a web application firewall (WAF).
  • D Create signed SSL certificates and use them to encrypt data between the forwarders and indexers.
Explanation

Universal forwarder log data travels to indexers. Encrypting that channel with trusted, signed SSL/TLS certificates protects the logs in transit and is appropriate for a production deployment.

Community Discussion

No comments yet. Be the first to start the discussion!