Knowledge Management

Is it possible to modify an indexed event?

charlescywong
New Member

Is it possible to modify an indexed event? My company is using Splunk for detecting suspicious activities. One of the scenarios is to detect Failed Logons to servers. I am afraid that someone (e.g. attacker) can modify the timestamp, username, or even delete the whole log to cover his/her track. Anyone know about this?

Any white paper or official document has been released regarding to the above question?

Thanks in advance!

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Data indexed in Splunk cannot be changed. That doesn't mean the source log can't be modified before it is indexed, however.
It's possible to delete data in Splunk (it's actually just marked as "invisible") by someone with the 'can_delete' privilege, but that's easily avoided by not granting the privilege to anyone.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Data indexed in Splunk cannot be changed. That doesn't mean the source log can't be modified before it is indexed, however.
It's possible to delete data in Splunk (it's actually just marked as "invisible") by someone with the 'can_delete' privilege, but that's easily avoided by not granting the privilege to anyone.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

Splunk is officially part of Cisco

Revolutionizing how our customers build resilience across their entire digital footprint.   Splunk ...

Splunk APM & RUM | Planned Maintenance March 26 - March 28, 2024

There will be planned maintenance for Splunk APM and RUM between March 26, 2024 and March 28, 2024 as ...