Hi,
Did any of you solve this? We are having the exact same problem when trying IT data block signing in our test environment.
This is what we did:
Stoped splunk.
Moved all old events in main-index to a new index.
Activated blockSignSize=100 to [main] in indexes.conf.
Started Splunk.
Everything work as it should except that Show Source says "Detected possible tampering with this source" on all events we check. We are running Splunk 5.0.6
Have also tried re-index the main index by running splunk clean eventdata -index main on the indexer and splunk clean all on the forwarder but that did not help.
Mia
... View more