We are running Splunk Enterprise on-premises and need to document our encryption-at-rest capabilities for a security/compliance requirement. Does Splunk Enterprise provide native encryption at rest for indexed data stored locally on Splunk indexers (hot, warm, and cold buckets)? If native encryption at rest is not provided for local index storage, is the recommended approach to implement encryption at the OS, filesystem, block-storage, or storage-array level (for example, LUKS/dm-crypt)? I am specifically asking about traditional on-premises local index storage, not Splunk Cloud or SmartStore. If possible, could you also provide a link to official Splunk documentation confirming this?
... View more