Add-ons and FIPS mode
FIPS mode is not currently supported by all Splunk-supported add-ons. Some add-ons with modular inputs use an encryption algorithm to store credentials. This encryption algorithm is not supported when FIPS is enabled on the Splunk platform. If you are required to use FIPS in your environment, the workaround for using this type of add-on is to install a heavy forwarder that is not using FIPS to perform data collection and then send that data to an indexer with FIPS enabled.
Additionally, if the add-on contains custom remediation commands, the remediation commands are not supported if FIPS is enabled on the search heads.
For more information about using FIPS with the Splunk platform, see About FIPS in the Securing Splunk Enterprise manual.
Syslog and timestamps
This documentation applies to the following versions of Splunk® Supported Add-ons: released