<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is our Windows Splunk forwarder displaying passwords in clear text in the password file? How do we encrypt it? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-our-Windows-Splunk-forwarder-displaying-passwords-in/m-p/231758#M45142</link>
    <description>&lt;P&gt;I feel It is a bug in Splunk. We have raised numerous cases with Splunk but in vain as the only recommendation they say is to put the password into "etc/system/local" !!   We tried putting encrypted password directly into the app, but it didn't work.&lt;/P&gt;

&lt;P&gt;If you analyse carefully, the password would have been encrypted and stored in another app's stanza. If you run btool on the client you would see the "stanza" in another app.  So the solution is&lt;BR /&gt;
- take the line of sslPassword out of the app and paste into  $SPLUNK_HOME/etc/system/local/.conf&lt;BR /&gt;
- Find the app which contains the sslPassword stanza which is encrypted.  Move the sslPassword stanza to that app&lt;/P&gt;

&lt;P&gt;I know, both of them are not perfect solutions.. but we couldn't find any other options. &lt;/P&gt;</description>
    <pubDate>Sat, 24 Jun 2017 09:36:53 GMT</pubDate>
    <dc:creator>koshyk</dc:creator>
    <dc:date>2017-06-24T09:36:53Z</dc:date>
    <item>
      <title>Why is our Windows Splunk forwarder displaying passwords in clear text in the password file? How do we encrypt it?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-our-Windows-Splunk-forwarder-displaying-passwords-in/m-p/231756#M45140</link>
      <description>&lt;P&gt;On the Windows side, the Splunk forwarder file displays clear text passwords. Can they be encrypted, and how?&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 17 Aug 2016 19:38:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-our-Windows-Splunk-forwarder-displaying-passwords-in/m-p/231756#M45140</guid>
      <dc:creator>regba123</dc:creator>
      <dc:date>2016-08-17T19:38:03Z</dc:date>
    </item>
    <item>
      <title>Re: Why is our Windows Splunk forwarder displaying passwords in clear text in the password file? How do we encrypt it?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-our-Windows-Splunk-forwarder-displaying-passwords-in/m-p/231757#M45141</link>
      <description>&lt;P&gt;Same is happening for me.  *nix forwarders are encrypting the sslPassword properly, but Windows forwarders are putting the hashed password somewhere else and leaving the initial configuration sslPassword in clear-text.  &lt;/P&gt;</description>
      <pubDate>Fri, 23 Jun 2017 18:27:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-our-Windows-Splunk-forwarder-displaying-passwords-in/m-p/231757#M45141</guid>
      <dc:creator>mckeon</dc:creator>
      <dc:date>2017-06-23T18:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why is our Windows Splunk forwarder displaying passwords in clear text in the password file? How do we encrypt it?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-our-Windows-Splunk-forwarder-displaying-passwords-in/m-p/231758#M45142</link>
      <description>&lt;P&gt;I feel It is a bug in Splunk. We have raised numerous cases with Splunk but in vain as the only recommendation they say is to put the password into "etc/system/local" !!   We tried putting encrypted password directly into the app, but it didn't work.&lt;/P&gt;

&lt;P&gt;If you analyse carefully, the password would have been encrypted and stored in another app's stanza. If you run btool on the client you would see the "stanza" in another app.  So the solution is&lt;BR /&gt;
- take the line of sslPassword out of the app and paste into  $SPLUNK_HOME/etc/system/local/.conf&lt;BR /&gt;
- Find the app which contains the sslPassword stanza which is encrypted.  Move the sslPassword stanza to that app&lt;/P&gt;

&lt;P&gt;I know, both of them are not perfect solutions.. but we couldn't find any other options. &lt;/P&gt;</description>
      <pubDate>Sat, 24 Jun 2017 09:36:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-our-Windows-Splunk-forwarder-displaying-passwords-in/m-p/231758#M45142</guid>
      <dc:creator>koshyk</dc:creator>
      <dc:date>2017-06-24T09:36:53Z</dc:date>
    </item>
  </channel>
</rss>

