Installation

FIPS mode in Splunk Enterprise

jkamdar
Path Finder

I installed Splunk Enterprise 9.2.0.1 without FIPS mode on and now I found out, I need to have it on. Luckily, I haven't done too much work, just one server and few Universal forwarders. 

 

I believe, I have to scrap the current installation of SH/Indexer and all the UFs, correct? There is not way to enable it in current install as far as I can tell.

 

Also, are there any files, I could save, so I can reuse them?

 

Labels (4)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

FIPS has to be turned on before starting Splunk.  If you've already started Splunk then you'll have to remove it and re-install it.  See https://docs.splunk.com/Documentation/Splunk/9.2.1/Security/SecuringSplunkEnterprisewithFIPS

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...

Out of the Box to Up And Running - Streamlined Observability for Your Cloud ...

  Tech Talk Streamlined Observability for Your Cloud Environment Register    Out of the Box to Up And Running ...

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...