I installed Splunk Enterprise 9.2.0.1 without FIPS mode on and now I found out, I need to have it on. Luckily, I haven't done too much work, just one server and few Universal forwarders.
I believe, I have to scrap the current installation of SH/Indexer and all the UFs, correct? There is not way to enable it in current install as far as I can tell.
Also, are there any files, I could save, so I can reuse them?
FIPS has to be turned on before starting Splunk. If you've already started Splunk then you'll have to remove it and re-install it. See https://docs.splunk.com/Documentation/Splunk/9.2.1/Security/SecuringSplunkEnterprisewithFIPS