<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Are logs still kept locally? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Are-logs-still-kept-locally/m-p/565815#M100643</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/238065"&gt;@mellqui&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If your trouble if for eventual modifications of the read log files, I can confirm that there isn't any modification of the local log files.&lt;/P&gt;&lt;P&gt;If instead your trouble is that there could be a modification of the logs before arriving to Splunk, it's possible as I describe below, it isn't possible to modify data after Splunk Indexing, or better ,if someone modify indexed data this is highlighted by an Integrity Check fail.&lt;/P&gt;&lt;P&gt;By default logs on forwarder, can be filtered (only Windows eventlog) on Forwarders but not modified.&lt;/P&gt;&lt;P&gt;It's possible to modify data on Indexers before indexing, e.g. to mask credit card numbers.&lt;/P&gt;&lt;P&gt;Then, after indexing, isn't possible to modify data.&lt;/P&gt;&lt;P&gt;In other words, analyzing the indexing process:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Obviously, you can modify a log before ingestion by the Forwarder, in this case, Splunk isn't able to check the data modification,&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;when data is ingested by the Forwarder, isn't possible to modify them until they arrive to indexer, eventually using SSL for securing the transmission,&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;When data arrive to the indexer, it's possing to modify them, but only using special configurations of the Indexers, but not manually,&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;after data are indexed they aren't modificable more.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;The modification by configurations (not manual) is also possible on intermediate Heavy Forwarders that works as an Indexer.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;In few words, if you control the process and the configurations, it's possible to modify Splunk data only if you want.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 03 Sep 2021 14:32:01 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2021-09-03T14:32:01Z</dc:date>
    <item>
      <title>Are logs still kept locally?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-logs-still-kept-locally/m-p/565805#M100641</link>
      <description>&lt;P&gt;Brand new to using the Universal Forwarder, and Splunk in general.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Question:&lt;/P&gt;&lt;P&gt;When using the forwarder/monitor, the logs on the forwarding server are still kept locally, correct? They aren't removed/modified in any way?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 14:08:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-logs-still-kept-locally/m-p/565805#M100641</guid>
      <dc:creator>mellqui</dc:creator>
      <dc:date>2021-09-03T14:08:39Z</dc:date>
    </item>
    <item>
      <title>Re: Are logs still kept locally?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-logs-still-kept-locally/m-p/565815#M100643</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/238065"&gt;@mellqui&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;If your trouble if for eventual modifications of the read log files, I can confirm that there isn't any modification of the local log files.&lt;/P&gt;&lt;P&gt;If instead your trouble is that there could be a modification of the logs before arriving to Splunk, it's possible as I describe below, it isn't possible to modify data after Splunk Indexing, or better ,if someone modify indexed data this is highlighted by an Integrity Check fail.&lt;/P&gt;&lt;P&gt;By default logs on forwarder, can be filtered (only Windows eventlog) on Forwarders but not modified.&lt;/P&gt;&lt;P&gt;It's possible to modify data on Indexers before indexing, e.g. to mask credit card numbers.&lt;/P&gt;&lt;P&gt;Then, after indexing, isn't possible to modify data.&lt;/P&gt;&lt;P&gt;In other words, analyzing the indexing process:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Obviously, you can modify a log before ingestion by the Forwarder, in this case, Splunk isn't able to check the data modification,&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;when data is ingested by the Forwarder, isn't possible to modify them until they arrive to indexer, eventually using SSL for securing the transmission,&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;When data arrive to the indexer, it's possing to modify them, but only using special configurations of the Indexers, but not manually,&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;after data are indexed they aren't modificable more.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;The modification by configurations (not manual) is also possible on intermediate Heavy Forwarders that works as an Indexer.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;In few words, if you control the process and the configurations, it's possible to modify Splunk data only if you want.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 14:32:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-logs-still-kept-locally/m-p/565815#M100643</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-09-03T14:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: Are logs still kept locally?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-logs-still-kept-locally/m-p/565830#M100644</link>
      <description>&lt;P&gt;Hey &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;I'm more less looking to see if the local log files are removed/transferred from the server when they are forwarded. We have other monitoring tools that use these logs.&lt;/P&gt;&lt;P&gt;Thanks for your reply.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 15:43:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-logs-still-kept-locally/m-p/565830#M100644</guid>
      <dc:creator>mellqui</dc:creator>
      <dc:date>2021-09-03T15:43:48Z</dc:date>
    </item>
    <item>
      <title>Re: Are logs still kept locally?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-logs-still-kept-locally/m-p/565839#M100645</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;If you have a splunk forwarder using a monitor input or a modular input to read local log files, it will just read them and forward them to splunk indexers.&lt;STRONG&gt; It does not delete the local logs.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The only exception&lt;/STRONG&gt; is if you are using a "&lt;STRONG&gt;batch&lt;/STRONG&gt;" inputs stanza with the&amp;nbsp;&lt;STRONG&gt;move_policy = sinkhole, &lt;/STRONG&gt;then splunk will read the file and delete it once finished (so you do not want to&amp;nbsp; use that for dynamic files, only static files). This is the mechanism used in the splunk "&lt;STRONG&gt;spooler&lt;/STRONG&gt;" inputs. (if you drop a file in the $SPLUNK/var/spool/splunk folder)&lt;/P&gt;&lt;P&gt;see&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.2/Data/Monitorfilesanddirectorieswithinputs.conf#Batch_syntax" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.2/Data/Monitorfilesanddirectorieswithinputs.conf#Batch_syntax&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Remarks&amp;nbsp; :&lt;/P&gt;&lt;P&gt;- keep in mind that your OS or application generating your log may have their own rotation/archive/deletion rules.&lt;BR /&gt;- Splunk internal logs (like $SPLUNK_HOME/var/log/splunk/*.log) do have their own rotation mechanism. So you may still find the recent ones locally, while a copy was ingested in splunk index=_internal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 16:17:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-logs-still-kept-locally/m-p/565839#M100645</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2021-09-03T16:17:52Z</dc:date>
    </item>
    <item>
      <title>Re: Are logs still kept locally?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-logs-still-kept-locally/m-p/565842#M100648</link>
      <description>&lt;P&gt;Hey &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/1357"&gt;@yannK&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This answers my question -- much appreciated!&lt;/P&gt;</description>
      <pubDate>Fri, 03 Sep 2021 16:55:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-logs-still-kept-locally/m-p/565842#M100648</guid>
      <dc:creator>mellqui</dc:creator>
      <dc:date>2021-09-03T16:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: Are logs still kept locally?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Are-logs-still-kept-locally/m-p/565895#M100651</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/238065"&gt;@mellqui&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma points are appreciated by all the Contributors &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Sep 2021 09:05:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Are-logs-still-kept-locally/m-p/565895#M100651</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-09-04T09:05:00Z</dc:date>
    </item>
  </channel>
</rss>

