<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Distributed Search Validate Audit Events in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Search-Validate-Audit-Events/m-p/86322#M3153</link>
    <description>&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/49406/did-something-change-with-the-audit-file-keys-between-42-and-43"&gt;http://splunk-base.splunk.com/answers/49406/did-something-change-with-the-audit-file-keys-between-42-and-43&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 10 Oct 2012 17:13:01 GMT</pubDate>
    <dc:creator>ephemeric</dc:creator>
    <dc:date>2012-10-10T17:13:01Z</dc:date>
    <item>
      <title>Distributed Search Validate Audit Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Search-Validate-Audit-Events/m-p/86321#M3152</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Is it possible to validate audit events from a search head on search peers?&lt;/P&gt;

&lt;P&gt;index=_audit splunk_server="host" | audit&lt;/P&gt;

&lt;P&gt;And as per the docs data blocks can only be validated on the indexer itself?&lt;/P&gt;

&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 12:36:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Search-Validate-Audit-Events/m-p/86321#M3152</guid>
      <dc:creator>ephemeric</dc:creator>
      <dc:date>2020-09-28T12:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed Search Validate Audit Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Search-Validate-Audit-Events/m-p/86322#M3153</link>
      <description>&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/49406/did-something-change-with-the-audit-file-keys-between-42-and-43"&gt;http://splunk-base.splunk.com/answers/49406/did-something-change-with-the-audit-file-keys-between-42-and-43&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2012 17:13:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Search-Validate-Audit-Events/m-p/86322#M3153</guid>
      <dc:creator>ephemeric</dc:creator>
      <dc:date>2012-10-10T17:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed Search Validate Audit Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Search-Validate-Audit-Events/m-p/86323#M3154</link>
      <description>&lt;P&gt;No, you cannot do this from a search head. Validation of audit events relies on linking events together so they form a chain where each event points to the previous event, and so on. When you issue a search from a search head, the search head is responsible for bringing all events from all search peers together and show them in whatever order you chose. When doing this, events from different search peers can and will be mixed in the search results, which results in that the search head won't be able to validate anything. The alternative would be for the search head to retrieve a bunch of extra events and hope that it has the correct certificates/keys for performing the validation, but that could very quickly get messy, especially considering that more complex searches would include commands that would cause search peers to return their results to the search head early in the search (&lt;CODE&gt;head&lt;/CODE&gt; is an example of a command that will cause this behaviour for instance).&lt;/P&gt;

&lt;P&gt;I agree with you that it would be elegant if the search peers could somehow validate the events before returning them to the search head, however this is as far as I know not currently possible.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Oct 2012 20:16:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Search-Validate-Audit-Events/m-p/86323#M3154</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-10-10T20:16:17Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed Search Validate Audit Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Search-Validate-Audit-Events/m-p/86324#M3155</link>
      <description>&lt;P&gt;Thank you, great help.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2012 09:10:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Search-Validate-Audit-Events/m-p/86324#M3155</guid>
      <dc:creator>ephemeric</dc:creator>
      <dc:date>2012-10-11T09:10:56Z</dc:date>
    </item>
    <item>
      <title>Re: Distributed Search Validate Audit Events</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Search-Validate-Audit-Events/m-p/86325#M3156</link>
      <description>&lt;P&gt;&lt;A href="http://splunk-base.splunk.com/answers/23183/block-signing-and-distributed-search"&gt;http://splunk-base.splunk.com/answers/23183/block-signing-and-distributed-search&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Oct 2012 09:18:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Distributed-Search-Validate-Audit-Events/m-p/86325#M3156</guid>
      <dc:creator>ephemeric</dc:creator>
      <dc:date>2012-10-11T09:18:39Z</dc:date>
    </item>
  </channel>
</rss>

