Getting Data In

Setting SSL password in inputs.conf but does not get encrypted after restart

horsefez
Motivator

Hi fellow splunkers,

I recently noticed a configuration error. I wrongly distributed the "[SSL] password= "via cluster-bundle to the indexers.
The problem as you might know is that the password gets not encrypted when it's on the indexers. And there is an even bigger problem to this, about duplicated apps.

Anyway...
I now tried to correct this fault, by deleting the "password = " entry in the .../etc/master_apps/_cluster/local/ on the master and distributed these settings to the indexer-cluster.
Then I went onto every indexer manually and added the [SSL] Stanza and "password= " entry to the .../etc/system/local/inputs.conf. After that I restarted splunkd on all of them.


Sadly this didn't encrypt the password. What could be wrong?

Thank you for your suggestions!
Best regards,
pyro_wood

0 Karma

mattlucas719
Explorer

the indexer is encrypting this inside it's /opt/splunk/etc/apps/directory as a copy of the app, it doesn't write it to the bundle directory found in slave-apps

0 Karma

mckeon
Explorer

password should be sslPassword, I believe.

0 Karma

jkat54
SplunkTrust
SplunkTrust

According to this:
http://docs.splunk.com/Documentation/Splunk/6.2.3/Security/Deploysecurepasswordsacrossmultipleserver...

It only encrypts the password in inputs.conf & outputs.conf if its found in a splunktcp-ssl stanza.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...