Security

Block Signing in Distributed Search Environment

Mahieu
Communicator

Hello Splunkers,

I'd like to configure Block Signing in an environment where I have two indexers in a cluster and a search head for distributed search on these two indexers.

From http://answers.splunk.com/answers/105289/difference-between-event-hashing-and-it-block-signing it looks like IT block signing is not available when distributed search is running.

I'm quite confused as it's an important feature in some tricky environments.

Is there a way to go around ?
Is there any roadmap regarding this feature ? I've seen that it's deprecated too so it doesn't look to good but ...

Thanks in advance for your help.

M.

1 Solution

Nomios
Engager

Hello,

Looks like the engineering team is working on it. Hopefully we'll have it soon.

View solution in original post

Nomios
Engager

Hello,

Looks like the engineering team is working on it. Hopefully we'll have it soon.

Mahieu
Communicator

Hello,

Can anyone from Splunk help maybe ?

Thanks a lot in advance.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Dynamic formatting from XML events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Stronger Security with Federated Search for S3, GCP SQL & Australian Threat ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...