For years, many of us in the Splunk community have relied on transport layer security (TLS) to secure traffic between Splunk components—forwarders, indexers, search heads, and more. TLS did the job: encrypt traffic, authenticate the server, and move on. But as the world shifted—toward a Zero Trust framework, tighter compliance, and more aggressive cyber threats—the age-old question resurfaced: "How do I really know who’s on the other end of that connection?"
Enter Mutual TLS (mTLS). In a world where verifying the server alone isn't enough, mTLS takes things up a notch. It requires both the server and the client to prove their identity. Think of it as cryptographically enforced mutual trust.
mTLS wasn’t just a checkbox feature. It was a response to what customers were asking for—and what regulators were starting to expect.
Here's what we heard:
So, we went to work. As of Splunk Enterprise 10.0, mTLS is now supported across 10 essential communication paths in your deployment—from forwarders and HTTP Event Collector (HEC) to clustered search heads and indexers.
We get it. When someone says “mTLS,” most admins think: "Ah, great…double the certificates, double the complexity." And yes, mTLS does need both sides to have certificates. That used to mean:
So, we tackled those, too:
In short, we're making mTLS secure and operationally manageable, even at an enterprise scale. This isn’t just a security feature—it’s a business enabler.
With Splunk Enterprise 10.0, you can now turn mTLS on for these connections:
Whether you’re preparing for an audit, adopting Zero Trust, or securing traffic between different regions (e.g. EMEA and APAC) — mTLS is a smart move. And it aligns with major frameworks:
With mTLS built into Splunk Enterprise 10.0, you’re a big step closer to meeting all of these—without needing extra tooling or agents.
Here’s how to begin:
You don’t have to turn everything on at once. Start with the most security-critical paths, validate, and expand from there.
mTLS is just the beginning. Here’s what else is coming:
We're building toward a world where security is both strong and seamless.
You asked us for stronger, smarter security.
You asked us for easier certificate management.
You asked us for Zero Trust readiness, without turning the Splunk platform into a full-time cert babysitting job.
mTLS in Splunk Enterprise 10.0 is the answer.
You now have the power to verify every connection, reduce attack surfaces, and meet the bar that your regulators set—without the pain of legacy Public Key Infrastructure (PKI) operations.
Ready to explore more?
Let’s raise the bar—together.
Welcome to a more trusted Splunk.
The world’s leading organizations rely on Splunk, a Cisco company, to continuously strengthen digital resilience with our unified security and observability platform, powered by industry-leading AI.
Our customers trust Splunk’s award-winning security and observability solutions to secure and improve the reliability of their complex digital environments, at any scale.