Splunk uses SSL/TLS to encrypt communication between components. By default, Splunk ships with self-signed certificates, but production environments should use proper CA-signed certs.
Web UI SSL is configured in web.conf. Inter-component SSL (forwarder-to-indexer, search head-to-peer) is configured in server.conf and outputs.conf.
Key settings: sslPassword (the password for the cert key), serverCert (path to the PEM file), and sslRootCAPath (trusted CA chain).