Splunk Search

how to stop splunk from editing files in /opt/splunk/etc/system/local/ directory?

neovenkat
Explorer

We want to stop splunk from editing the files inside $SPLUNKHOME/etc/system/local, for example its adds sslKeysPassword to server.conf, password to inputs.conf on its own. Thanks in advance!

Tags (1)
0 Karma

strive
Influencer

Even i have seen this behavior. You need not add the attributes sslKeysPassword and password to server.conf and inputs.conf respectively. Without you entering these attributes, splunk adds them.

See my other post: https://answers.splunk.com/answers/643307/why-is-the-ssl-connection-between-forwarder-and-in.html

In my case:
a. in server.conf, i did not even have [sslConfig] stanza. Splunk adds that and underneath sslKeysPassword attribute also.
b. In inputs.conf, i had [SSL] stanza but not password attribute. During restart splunk adds password attribute.

0 Karma

skoelpin
SplunkTrust
SplunkTrust

Why? Some changes are necessary to etc/system/local so they take precedence

damien_chillet
Builder

Splunk does edit these values but it's because it's encrypting them after you enter them manually usually.

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...