Security

Block Signing in Distributed Search Environment

Mahieu
Communicator

Hello Splunkers,

I'd like to configure Block Signing in an environment where I have two indexers in a cluster and a search head for distributed search on these two indexers.

From http://answers.splunk.com/answers/105289/difference-between-event-hashing-and-it-block-signing it looks like IT block signing is not available when distributed search is running.

I'm quite confused as it's an important feature in some tricky environments.

Is there a way to go around ?
Is there any roadmap regarding this feature ? I've seen that it's deprecated too so it doesn't look to good but ...

Thanks in advance for your help.

M.

1 Solution

Nomios
Engager

Hello,

Looks like the engineering team is working on it. Hopefully we'll have it soon.

View solution in original post

Nomios
Engager

Hello,

Looks like the engineering team is working on it. Hopefully we'll have it soon.

Mahieu
Communicator

Hello,

Can anyone from Splunk help maybe ?

Thanks a lot in advance.

0 Karma
Get Updates on the Splunk Community!

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...