Steps for securing your Splunk Enterprise deployment with TLS

The general workflow to secure your Splunk platform deployment with TLS follows:

  1. Decide how you want to secure your Splunk platform deployment. This determines how much securing work you actually do.
    • If you use Splunk Cloud Platform, your Splunk Cloud Platform infrastructure already has certificates that protect it. Splunk provides and maintains these certificates, including the certificates that protect connection between forwarders and SCP.. You can consider the following options for the data collection and forwarding infrastructure that you manage and that sends data to your Splunk Cloud Platform instance.
    • You can choose to secure communications between Splunk Web and your browser, or Splunk Web and the Splunk platform deployment
    • You can also secure communications between individual Splunk platform instances. This is similar to securing Splunk Web, but has a slightly different procedure
    • You can secure both of these types of communication. This provides the best level of security but takes additional time and requires a better understanding of your Splunk platform deployment and its position in the network.
  2. Obtain the TLS certificates that you need to secure the deployment in the way you want
    • You can get the certificates from a third party, or
    • You can create the certificates yourself
  3. Verify that the certificates are valid
  4. Install the certificates on each Splunk platform instance
  5. Configure each Splunk platform instance to use the certificates
  6. If necessary, configure your domain name service (DNS) registry to account for the information that the certificates contain
  7. Test and troubleshoot

Note: This topic is a high-level workflow for obtaining and installing certificates for Splunk Platform instances that you manage. It does not contain specifics on configurations, certificate store locations, or certificate composition requirements. See the links in each section that follows for specific details on that section, or read through the topic and proceed to the Next Steps section to continue into each section to begin installing and configuring certificates.

Next Steps

If you have a Splunk Cloud Platform deployment with external infrastructure that forwards data to it, see the following topic to configure the universal forwarder credentials package on that forwarding infrastructure:

If you have a Splunk Enterprise deployment, read on to understand the next steps for securing the infrastructure with certificates.

Now that you understand the overall procedure for using TLS certificates with your Splunk platform deployment, you need some certificates to work with if you don't already have them. Choose from one of the following links for specific instructions on getting or creating the certificates.