<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Splunk with Archive Solution in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-with-Archive-Solution/m-p/538217#M4839</link>
    <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;I have to build a temper-proof archive solution with data ingested in splunk. The last couple days I thought about it and I would appreciate your ideas or at best a known/experienced Best Practice advice.&lt;/P&gt;&lt;P&gt;The idea behind this is to forward or store splunk indexed data temper-proof (and non deleteable), so that I can be sure the data CAN NOT be altered anymore.&lt;/P&gt;&lt;P&gt;Recently I build this with a indexer forwarding to a syslog-server (syslog-format), the data then is copied to a WORM-Storage. But I am not convinced that this solution is the ideal one. It works, but there are a few to much "error-sources" in the chain.&lt;/P&gt;&lt;P&gt;The other idea is to use the data integrity function to ensure, that the data is not altered and still valid. If Iam right, the indexed data can only be deleted but not altered? I am also convied of this idea, because I had to handle the checksum files and this could be a lot with 250GB indexed data per day.&lt;/P&gt;&lt;P&gt;In sum there are two ideas:&lt;/P&gt;&lt;P&gt;Target: temper-proof/non-deleteable data from indexed events // a goodie would be a fully seured transport of the data&lt;/P&gt;&lt;P&gt;1. IDX Forward (syslog-format) -&amp;gt; Syslog-Server -&amp;gt; Copy to WORM-Storage&lt;/P&gt;&lt;P&gt;2. Use data integrity function -&amp;gt; Store Checksums in WORM-Storage, because the data itself can only be deleted.&lt;/P&gt;&lt;P&gt;I hope some of you built such a archive solution in the past and can help me out.&lt;/P&gt;&lt;P&gt;BR, Tom&lt;/P&gt;</description>
    <pubDate>Tue, 02 Feb 2021 06:25:01 GMT</pubDate>
    <dc:creator>sscholz</dc:creator>
    <dc:date>2021-02-02T06:25:01Z</dc:date>
    <item>
      <title>Splunk with Archive Solution</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-with-Archive-Solution/m-p/538217#M4839</link>
      <description>&lt;P&gt;Hello Community,&lt;/P&gt;&lt;P&gt;I have to build a temper-proof archive solution with data ingested in splunk. The last couple days I thought about it and I would appreciate your ideas or at best a known/experienced Best Practice advice.&lt;/P&gt;&lt;P&gt;The idea behind this is to forward or store splunk indexed data temper-proof (and non deleteable), so that I can be sure the data CAN NOT be altered anymore.&lt;/P&gt;&lt;P&gt;Recently I build this with a indexer forwarding to a syslog-server (syslog-format), the data then is copied to a WORM-Storage. But I am not convinced that this solution is the ideal one. It works, but there are a few to much "error-sources" in the chain.&lt;/P&gt;&lt;P&gt;The other idea is to use the data integrity function to ensure, that the data is not altered and still valid. If Iam right, the indexed data can only be deleted but not altered? I am also convied of this idea, because I had to handle the checksum files and this could be a lot with 250GB indexed data per day.&lt;/P&gt;&lt;P&gt;In sum there are two ideas:&lt;/P&gt;&lt;P&gt;Target: temper-proof/non-deleteable data from indexed events // a goodie would be a fully seured transport of the data&lt;/P&gt;&lt;P&gt;1. IDX Forward (syslog-format) -&amp;gt; Syslog-Server -&amp;gt; Copy to WORM-Storage&lt;/P&gt;&lt;P&gt;2. Use data integrity function -&amp;gt; Store Checksums in WORM-Storage, because the data itself can only be deleted.&lt;/P&gt;&lt;P&gt;I hope some of you built such a archive solution in the past and can help me out.&lt;/P&gt;&lt;P&gt;BR, Tom&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 06:25:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-with-Archive-Solution/m-p/538217#M4839</guid>
      <dc:creator>sscholz</dc:creator>
      <dc:date>2021-02-02T06:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk with Archive Solution</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-with-Archive-Solution/m-p/538224#M4840</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Some comments and my own opinions.&lt;/P&gt;&lt;P&gt;IMHO: as long as data can be accessed / modified somehow from servers/network I don't call it as archive. Event those files in splunk warm and cold data can be edited from os level if someone really wants. Also those checksum files can edited unless those are in WORM.I think that both of your options are ok. Both have their pros and cons.&lt;/P&gt;&lt;P&gt;1) you could later index/use that data even &amp;nbsp;other tools than splunk. Other side this generates additional requirements and &amp;nbsp;needs that this system is working all time or otherwise your splunk will stop.&lt;/P&gt;&lt;P&gt;2) This need some scripting to get those checksum files to stored into WORM as soon as those are created. Actually this creation can do automatically by splunk (see indexes.conf / enableDataIntegrityControl + singntool)&lt;/P&gt;&lt;P&gt;Third option is use real archiving system to store needed events outside of splunk.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 07:36:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-with-Archive-Solution/m-p/538224#M4840</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-02-02T07:36:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk with Archive Solution</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-with-Archive-Solution/m-p/538246#M4842</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/231106"&gt;@sscholz&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I want to make an addition to&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;comments regarding required disk space for checksum files.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splunk stores a hash which is of 32 bytes in length for every slices. Default slice size of 128 KB.&lt;BR /&gt;So for 250GB/day ingesting you will need about 62.5 MB daily for checksums. You should also multiple this size by replication factor.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Feb 2021 09:25:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-with-Archive-Solution/m-p/538246#M4842</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-02T09:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk with Archive Solution</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-with-Archive-Solution/m-p/538987#M4896</link>
      <description>&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;So I think I had to stick to my syslog solution. &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;BR, Tom&lt;/P&gt;</description>
      <pubDate>Mon, 08 Feb 2021 12:46:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Splunk-with-Archive-Solution/m-p/538987#M4896</guid>
      <dc:creator>sscholz</dc:creator>
      <dc:date>2021-02-08T12:46:48Z</dc:date>
    </item>
  </channel>
</rss>

