Knowledge Management

Is it possible to modify an indexed event?

charlescywong
New Member

Is it possible to modify an indexed event? My company is using Splunk for detecting suspicious activities. One of the scenarios is to detect Failed Logons to servers. I am afraid that someone (e.g. attacker) can modify the timestamp, username, or even delete the whole log to cover his/her track. Anyone know about this?

Any white paper or official document has been released regarding to the above question?

Thanks in advance!

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Data indexed in Splunk cannot be changed. That doesn't mean the source log can't be modified before it is indexed, however.
It's possible to delete data in Splunk (it's actually just marked as "invisible") by someone with the 'can_delete' privilege, but that's easily avoided by not granting the privilege to anyone.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Data indexed in Splunk cannot be changed. That doesn't mean the source log can't be modified before it is indexed, however.
It's possible to delete data in Splunk (it's actually just marked as "invisible") by someone with the 'can_delete' privilege, but that's easily avoided by not granting the privilege to anyone.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...