Getting Data In

remote.s3.access_key and remote.s3.secret_key are overwritten after apply cluster-bundle

ltang78
Engager

On cluster master one of $SPLUNK_HOME/etc/master-apps/<app-name>/local/indexes.conf, I set remote.s3.access_key and remote.s3.secret_key with the same access_key and secret_key used with s3cmd. However after apply cluster-bundle, the indexes.conf is updated and both key values are replaced. The new set of keys not only replace the ones under [default] stanza, but also on each index stanza. 

Where the new keys come from? Is it expected that keys be overwritten?

Labels (2)
Tags (1)
0 Karma

ltang78
Engager

Yes. Starts with $7. Thanks for the reply

0 Karma

PaulPanther
Builder

Do the "new" keys start with $7$? If yes, they are encrypted.

Get Updates on the Splunk Community!

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

A Guide To Cloud Migration Success

As enterprises’ rapid expansion to the cloud continues, IT leaders are continuously looking for ways to focus ...

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...