Getting Data In

remote.s3.access_key and remote.s3.secret_key are overwritten after apply cluster-bundle

ltang78
Engager

On cluster master one of $SPLUNK_HOME/etc/master-apps/<app-name>/local/indexes.conf, I set remote.s3.access_key and remote.s3.secret_key with the same access_key and secret_key used with s3cmd. However after apply cluster-bundle, the indexes.conf is updated and both key values are replaced. The new set of keys not only replace the ones under [default] stanza, but also on each index stanza. 

Where the new keys come from? Is it expected that keys be overwritten?

Labels (2)
Tags (1)
0 Karma

ltang78
Engager

Yes. Starts with $7. Thanks for the reply

0 Karma

PaulPanther
Motivator

Do the "new" keys start with $7$? If yes, they are encrypted.

Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...