Deployment Architecture

How can I make a PCI audit.rules generates fewer events or logs?

ams44splunk
New Member

How do I reduce the number of log messages and maintain PCI compliant auditing? The audit.rules generates too much data. The rules audit more than 50 system calls and can swamp my log server. The rules audit every system call we identified as matching a requirement of the Payment Card Industry (PCI) Data Security Standard.

0 Karma

cgkades
Explorer

No one knew the answer to this?! I have similar issues with security compliance. I wish they could just do a tail -f on the log

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...