Security

Are there any new resources on Splunk On Prem Data Integrity and Anti Tamper Controls?

NightShark
Path Finder

Hello,

I have looked over blogs and topics being discussed about Splunk's Data Integrity Checks and Anti Tampering controls, yet most of the resources found were outdated and/or not found anymore.

Are there any new sources or apps that keep track of Splunk's own security from its Admins via the configuration tracker index or other means?

Thanks,
Best Regards,

Labels (2)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

@NightShark - For the 1st item I know you (as a admin user) will see a message on the Splunk screen as shown here in the screenshot, that's where you will see that message.

VatsalJagani_0-1692619827732.png

 

View solution in original post

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@NightShark - Splunk has two things for it:

  1. Splunk gives error for file hash not matching if it finds files being updated/deleted which not suppose to change.
  2. It has a configuration changes tracker. Search for index=_configtracker

 

I hope this helps!!!

0 Karma

NightShark
Path Finder

Hello @VatsalJagani,

Thank you for your response, what is that feature called about giving an alert when hashes do not match?

Second of all, is there a list of specific configuration changes that could allow us to tamper with the data before being sent to the indexers like sed being added for example in the configuration files?

Thanks,

Regards,

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@NightShark - For the 1st item I know you (as a admin user) will see a message on the Splunk screen as shown here in the screenshot, that's where you will see that message.

VatsalJagani_0-1692619827732.png

 

0 Karma
Get Updates on the Splunk Community!

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...

Database Performance Sidebar Panel Now on APM Database Query Performance & Service ...

We’ve streamlined the troubleshooting experience for database-related service issues by adding a database ...