<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Log Retention in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Log-Retention/m-p/38084#M6983</link>
    <description>&lt;P&gt;Hello MW, Thank you for the valuable answer. With regards to my query, i can see that this is possible only in licensed version-is that true? if not then please guide me in setting up the retention policy&lt;/P&gt;</description>
    <pubDate>Tue, 12 Jul 2011 12:52:10 GMT</pubDate>
    <dc:creator>infosec_skrc</dc:creator>
    <dc:date>2011-07-12T12:52:10Z</dc:date>
    <item>
      <title>Log Retention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-Retention/m-p/38082#M6981</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;

&lt;P&gt;I've studied that Splunk is capable of retenting the original logs feed in to it, also audit the changes if any done to those original logs. Is this correct?&lt;BR /&gt;
If yes, I could not find the related docs to configure so. I am running Splunk 4.2 free version. I need the original logs for audit purpose.Can someone help me in this.. Thanks in advance&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2011 12:26:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-Retention/m-p/38082#M6981</guid>
      <dc:creator>infosec_skrc</dc:creator>
      <dc:date>2011-07-05T12:26:21Z</dc:date>
    </item>
    <item>
      <title>Re: Log Retention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-Retention/m-p/38083#M6982</link>
      <description>&lt;P&gt;Splunk does retain the original event.  You can configure block signing to verify the integrity of those events (as they were stored in the Splunk index): &lt;A href="http://www.splunk.com/base/Documentation/latest/admin/ITDataSigning"&gt;http://www.splunk.com/base/Documentation/latest/admin/ITDataSigning&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jul 2011 12:46:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-Retention/m-p/38083#M6982</guid>
      <dc:creator>mw</dc:creator>
      <dc:date>2011-07-05T12:46:19Z</dc:date>
    </item>
    <item>
      <title>Re: Log Retention</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Log-Retention/m-p/38084#M6983</link>
      <description>&lt;P&gt;Hello MW, Thank you for the valuable answer. With regards to my query, i can see that this is possible only in licensed version-is that true? if not then please guide me in setting up the retention policy&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jul 2011 12:52:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Log-Retention/m-p/38084#M6983</guid>
      <dc:creator>infosec_skrc</dc:creator>
      <dc:date>2011-07-12T12:52:10Z</dc:date>
    </item>
  </channel>
</rss>

