Getting Data In

remote.s3.access_key and remote.s3.secret_key are overwritten after apply cluster-bundle

ltang78
Engager

On cluster master one of $SPLUNK_HOME/etc/master-apps/<app-name>/local/indexes.conf, I set remote.s3.access_key and remote.s3.secret_key with the same access_key and secret_key used with s3cmd. However after apply cluster-bundle, the indexes.conf is updated and both key values are replaced. The new set of keys not only replace the ones under [default] stanza, but also on each index stanza. 

Where the new keys come from? Is it expected that keys be overwritten?

Labels (2)
Tags (1)
0 Karma

ltang78
Engager

Yes. Starts with $7. Thanks for the reply

0 Karma

PaulPanther
Builder

Do the "new" keys start with $7$? If yes, they are encrypted.

Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...