<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk database log manipulation in Security</title>
    <link>https://community.splunk.com/t5/Security/Splunk-database-log-manipulation/m-p/400491#M9697</link>
    <description>&lt;P&gt;Greetings,&lt;/P&gt;

&lt;P&gt;I had a question in regards to accessing and manipulating Splunk logs. All of my Splunk infrastructure is onsite. &lt;/P&gt;

&lt;P&gt;For example, what would be required for someone to manually modify my Firewall logs or Active Directory logs that reside on my indexer or heavy forwarder? If possessing the right privileges, could a user modify a firewall log on in a Splunk database to change the source or destination IP (or whatever log information) in a firewall log, or delete that particular log event itself? &lt;/P&gt;

&lt;P&gt;I was not sure what permissions and databases / files would be involved.&lt;/P&gt;</description>
    <pubDate>Mon, 18 Feb 2019 17:55:11 GMT</pubDate>
    <dc:creator>johann2017</dc:creator>
    <dc:date>2019-02-18T17:55:11Z</dc:date>
    <item>
      <title>Splunk database log manipulation</title>
      <link>https://community.splunk.com/t5/Security/Splunk-database-log-manipulation/m-p/400491#M9697</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;

&lt;P&gt;I had a question in regards to accessing and manipulating Splunk logs. All of my Splunk infrastructure is onsite. &lt;/P&gt;

&lt;P&gt;For example, what would be required for someone to manually modify my Firewall logs or Active Directory logs that reside on my indexer or heavy forwarder? If possessing the right privileges, could a user modify a firewall log on in a Splunk database to change the source or destination IP (or whatever log information) in a firewall log, or delete that particular log event itself? &lt;/P&gt;

&lt;P&gt;I was not sure what permissions and databases / files would be involved.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Feb 2019 17:55:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-database-log-manipulation/m-p/400491#M9697</guid>
      <dc:creator>johann2017</dc:creator>
      <dc:date>2019-02-18T17:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk database log manipulation</title>
      <link>https://community.splunk.com/t5/Security/Splunk-database-log-manipulation/m-p/400492#M9698</link>
      <description>&lt;P&gt;Hi @johann2017 &lt;/P&gt;

&lt;P&gt;There is no way that someone using Splunk can easily change data such as changing the source and destination IPs. If the user has the &lt;CODE&gt;can_delete&lt;/CODE&gt; capability (can be added to a role in Settings &lt;CODE&gt;&amp;gt;&lt;/CODE&gt;Access Controls &lt;CODE&gt;&amp;gt;&lt;/CODE&gt;Roles) they can specifically delete bits of to prevent them from being found.  Restricting access to this capability is typically the protection that most customers require against data &lt;EM&gt;changes&lt;/EM&gt;.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;|delete&lt;/CODE&gt; can be reversed if you have filesystem access.  If someone has access to the filesystem, they could conceivably change the data. - But this would be a huge amount of effort. They would need to reingest the whole bucket with the altered records. &lt;/P&gt;

&lt;P&gt;There is this blog article that might be of interest to you: &lt;A href="https://www.splunk.com/blog/2015/10/28/data-integrity-is-back-baby.html"&gt;https://www.splunk.com/blog/2015/10/28/data-integrity-is-back-baby.html&lt;/A&gt; Note data integrity is not needed for most customers.&lt;/P&gt;

&lt;P&gt;All the best.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Feb 2019 19:52:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-database-log-manipulation/m-p/400492#M9698</guid>
      <dc:creator>chrisyounger</dc:creator>
      <dc:date>2019-02-18T19:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk database log manipulation</title>
      <link>https://community.splunk.com/t5/Security/Splunk-database-log-manipulation/m-p/400493#M9699</link>
      <description>&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 19 Feb 2019 00:14:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Splunk-database-log-manipulation/m-p/400493#M9699</guid>
      <dc:creator>johann2017</dc:creator>
      <dc:date>2019-02-19T00:14:59Z</dc:date>
    </item>
  </channel>
</rss>

