Getting Data In

Is it possible to encrypt traffic between the forwarder and indexer, but store the collected logs in clear text?

New Member

I am using the latest universal forwarder and I enabled SSL encryption. The collected logs stored are encrypted in the indexes path C:\Program Files\Splunk\var\lib\splunk\Index_Name\db, but need to encrypt traffic between the indexer and forwarder only and store log files as is in the indexer server (Clear text).
Is this possible ?


0 Karma

Splunk Employee
Splunk Employee

Not really, the data in splunk is in a particular format (the splunk index/bucket file storage)
so it is not in clear.

You could eventually export the result of search over the data in a "raw" format. But it will not be practical if you want to export all our data all the time.

0 Karma
Get Updates on the Splunk Community!

Happy CX Day to our Community Superheroes!

Happy 10th Birthday CX Day!What is CX Day? It’s a global celebration recognizing innovation and success in the ...

Check out This Month’s Brand new Splunk Lantern Articles

Splunk Lantern is a customer success center providing advice from Splunk experts on valuable data insights, ...

Routing Data to Different Splunk Indexes in the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...