<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to detect data supression in Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-detect-data-supression-in-Splunk/m-p/492962#M84263</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;There are few ways to suppress data in Splunk, like  &lt;CODE&gt;| delete&lt;/CODE&gt; command from search menu or  &lt;CODE&gt;splunk clean eventdata&lt;/CODE&gt; from shell. I wondering to know if there is a simple way to generate an alert when someone suppress data from Splunk.&lt;/P&gt;

&lt;P&gt;Thanks for the help.&lt;/P&gt;</description>
    <pubDate>Wed, 18 Mar 2020 16:05:45 GMT</pubDate>
    <dc:creator>woodentree</dc:creator>
    <dc:date>2020-03-18T16:05:45Z</dc:date>
    <item>
      <title>How to detect data supression in Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-detect-data-supression-in-Splunk/m-p/492962#M84263</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;There are few ways to suppress data in Splunk, like  &lt;CODE&gt;| delete&lt;/CODE&gt; command from search menu or  &lt;CODE&gt;splunk clean eventdata&lt;/CODE&gt; from shell. I wondering to know if there is a simple way to generate an alert when someone suppress data from Splunk.&lt;/P&gt;

&lt;P&gt;Thanks for the help.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Mar 2020 16:05:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-detect-data-supression-in-Splunk/m-p/492962#M84263</guid>
      <dc:creator>woodentree</dc:creator>
      <dc:date>2020-03-18T16:05:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to detect data supression in Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-detect-data-supression-in-Splunk/m-p/492963#M84264</link>
      <description>&lt;P&gt;You could search remote_searches.log for "| delete". &lt;BR /&gt;
To find CLI commands, you have to be indexing the .bash_history file of every user who can run the &lt;CODE&gt;splunk clean&lt;/CODE&gt; command.  Then it's a simple matter to search command histories for the command.&lt;/P&gt;

&lt;P&gt;A clarification: &lt;CODE&gt;splunk clean eventdata&lt;/CODE&gt; does not &lt;EM&gt;suppress&lt;/EM&gt; data, it &lt;EM&gt;erases&lt;/EM&gt; it.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:39:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-detect-data-supression-in-Splunk/m-p/492963#M84264</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-09-30T04:39:53Z</dc:date>
    </item>
    <item>
      <title>Re: How to detect data supression in Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-detect-data-supression-in-Splunk/m-p/492964#M84265</link>
      <description>&lt;P&gt;Thanks for the help!&lt;/P&gt;</description>
      <pubDate>Fri, 20 Mar 2020 13:44:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-detect-data-supression-in-Splunk/m-p/492964#M84265</guid>
      <dc:creator>woodentree</dc:creator>
      <dc:date>2020-03-20T13:44:42Z</dc:date>
    </item>
  </channel>
</rss>

