Getting Data In

Is it possible to encrypt traffic between the forwarder and indexer, but store the collected logs in clear text?

hatemshaderma
New Member

I am using the latest universal forwarder and I enabled SSL encryption. The collected logs stored are encrypted in the indexes path C:\Program Files\Splunk\var\lib\splunk\Index_Name\db, but need to encrypt traffic between the indexer and forwarder only and store log files as is in the indexer server (Clear text).
Is this possible ?

Thanks.

0 Karma

yannK
Splunk Employee
Splunk Employee

Not really, the data in splunk is in a particular format (the splunk index/bucket file storage)
so it is not in clear.

You could eventually export the result of search over the data in a "raw" format. But it will not be practical if you want to export all our data all the time.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...