Security

Can Splunk encryption and compression be completely disabled?

grwright5
New Member

We have a Pure FlashArray which can offload compression and encryption and do a much better job of data reduction overall if the Splunk compression and encryption features can be deactivated. Is this possible now? If not, can it be added please?

Tags (2)
0 Karma

Ayn
Legend

You can configure both Splunk's web server and the Splunk daemon itself not to use SSL, if that's what you mean. I'm highly sceptical to your claims about that it would do a much better job though, and you will possibly run into certificate issues.

0 Karma

yoho
Contributor

I think he's talking about encryption and compression on disk as he is mentioning Pure Flash Array. By default, data is compressed but not encrypted. There used to be a parameter to disable encryption but it's now obsolete (see indexes.conf documentation )

compressRawdata = true|false
* This parameter is ignored. The splunkd process always compresses raw data.

0 Karma
Get Updates on the Splunk Community!

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...