Getting Data In

remote.s3.access_key and remote.s3.secret_key are overwritten after apply cluster-bundle

ltang78
Engager

On cluster master one of $SPLUNK_HOME/etc/master-apps/<app-name>/local/indexes.conf, I set remote.s3.access_key and remote.s3.secret_key with the same access_key and secret_key used with s3cmd. However after apply cluster-bundle, the indexes.conf is updated and both key values are replaced. The new set of keys not only replace the ones under [default] stanza, but also on each index stanza. 

Where the new keys come from? Is it expected that keys be overwritten?

Labels (2)
Tags (1)
0 Karma

ltang78
Engager

Yes. Starts with $7. Thanks for the reply

0 Karma

PaulPanther
Motivator

Do the "new" keys start with $7$? If yes, they are encrypted.

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...