Application-layer authentication for forwarders and indexers
Application-layer authentication provides additional assurance about the identities of forwarders and indexers in Splunk-to-Splunk (S2S) connections, in addition to the transport security provided by TLS.
You can strengthen the security of Splunk-to-Splunk (S2S) communication by configuring application-layer authentication between forwarders and indexers. Application-layer authentication adds an authentication exchange above the transport security provided by Transport Layer Security (TLS) and provides additional assurance about the identities of the participants in each S2S connection.
Application-layer authentication provides a separate authentication outcome for each forwarder-to-indexer connection. Splunk software records authentication outcomes in logs and provides metrics that you can use to monitor authentication across S2S connections. The authentication exchange operates in audit mode, so it validates and reports authentication outcomes without interrupting data flow.
For more information about how application-layer authentication works, its security benefits, monitoring authentication outcomes, and how to configure the capability, see Application-layer authentication for forwarders and indexers.