Getting Data In

Is it possible to encrypt traffic between the forwarder and indexer, but store the collected logs in clear text?

New Member

I am using the latest universal forwarder and I enabled SSL encryption. The collected logs stored are encrypted in the indexes path C:\Program Files\Splunk\var\lib\splunk\Index_Name\db, but need to encrypt traffic between the indexer and forwarder only and store log files as is in the indexer server (Clear text).
Is this possible ?


0 Karma

Splunk Employee
Splunk Employee

Not really, the data in splunk is in a particular format (the splunk index/bucket file storage)
so it is not in clear.

You could eventually export the result of search over the data in a "raw" format. But it will not be practical if you want to export all our data all the time.

0 Karma
Get Updates on the Splunk Community!

How I Instrumented a Rust Application Without Knowing Rust

As a technical writer, I often have to edit or create code snippets for Splunk's distributions of ...

Splunk Community Platform Survey

Hey Splunk Community, Starting today, the community platform may prompt you to participate in a survey. The ...

Observability Highlights | November 2022 Newsletter

 November 2022Observability CloudEnd Of Support Extension for SignalFx Smart AgentSplunk is extending the End ...