We are wondering if the Splunk forwarders care if SSL termination is not done at the indexer? We would like the forwarder to have the SSL cert of our NG firewall, which will then decrypt the traffic and send it to an indexer. Will this work? Does it need to be a direct connect from the fwd to the indexer?
Thanks!
↧