Installation

FIPS mode in Splunk Enterprise

jkamdar
Communicator

I installed Splunk Enterprise 9.2.0.1 without FIPS mode on and now I found out, I need to have it on. Luckily, I haven't done too much work, just one server and few Universal forwarders. 

 

I believe, I have to scrap the current installation of SH/Indexer and all the UFs, correct? There is not way to enable it in current install as far as I can tell.

 

Also, are there any files, I could save, so I can reuse them?

 

Labels (4)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

FIPS has to be turned on before starting Splunk.  If you've already started Splunk then you'll have to remove it and re-install it.  See https://docs.splunk.com/Documentation/Splunk/9.2.1/Security/SecuringSplunkEnterprisewithFIPS

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...