Hello, has anyone ever put splunkdb in a truecrypt encrypted volume succesfully? Thanks,
Luca.
I have not, but if you are able to successfully run the following command on the volume, all should be well:
./splunk cmd locktest
I am not 100% sure that a service will be able to mount a truecrypt volume without an interactive logon. It may be possible, but in either case you will still see a performance penalty since every read/write operation will have to be de/encrypted before splunk has access to the data. Since splunk is quite disk intensive during indexing/searching, this overhead may lead to a very sluggish system performance.
I'd say just try it out on a dev system and report back with your findings for the good of the community 🙂
I have not, but if you are able to successfully run the following command on the volume, all should be well:
./splunk cmd locktest