Curious what version Splunk are you running? We recently had I/O issues on 8.0.1. Started spontaneously a couple of weekends ago.
Restarting individual indexers resolved it.
... View more
When deploying a new EC cert, the critical step was invoking FIPS when encrypting the key with a passphrase:
$ OPENSSL_FIPS=1 openssl ec -aes256 -in splunkforwarders.key -out splunkforwarders.enc.key
I didn't need to invoke FIPS when generating the key, or the CSR. Just when passphrasing the key.
... View more