<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to optimize Splunk for PCI Compliance? in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-optimize-Splunk-for-PCI-Compliance/m-p/324637#M2983</link>
    <description>&lt;P&gt;The PCI Compliance App is far from free; several hundred thousand dollars. &lt;/P&gt;</description>
    <pubDate>Wed, 08 Apr 2020 14:11:30 GMT</pubDate>
    <dc:creator>cly</dc:creator>
    <dc:date>2020-04-08T14:11:30Z</dc:date>
    <item>
      <title>How to optimize Splunk for PCI Compliance?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-optimize-Splunk-for-PCI-Compliance/m-p/324632#M2978</link>
      <description>&lt;P&gt;Has anyone developed guidelines for what should be (and should not be) logged in Splunk for PCI Compliance audits? Referring specifically to the storage and data management requirements as described in the Information Security Forum (ISF) Standard of Good Practice (SoGP), the Payment Card Industry Data Security Standard (PCI DSS), ISO 27001, and US National Institute for&lt;BR /&gt;
Standards and Technology (NIST) Cybersecurity Framework. We don't want to "log everything" so I'm curious if there are best practices regarding what to log - e.g., log data related to ABC requirements because Splunk processing is needed, but data related to XYZ requirements can be logged elsewhere because Splunk processing is not needed.   Any help and guidance is greatly appreciated. &lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 13:37:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-optimize-Splunk-for-PCI-Compliance/m-p/324632#M2978</guid>
      <dc:creator>JimSchlaker</dc:creator>
      <dc:date>2017-09-06T13:37:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to optimize Splunk for PCI Compliance?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-optimize-Splunk-for-PCI-Compliance/m-p/324633#M2979</link>
      <description>&lt;P&gt;Check out the free Splunk App for PCI Compliance at &lt;A href="https://splunkbase.splunk.com/app/1143/"&gt;https://splunkbase.splunk.com/app/1143/&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 13:58:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-optimize-Splunk-for-PCI-Compliance/m-p/324633#M2979</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-09-06T13:58:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to optimize Splunk for PCI Compliance?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-optimize-Splunk-for-PCI-Compliance/m-p/324634#M2980</link>
      <description>&lt;P&gt;Thanks for the link to the PCI Compliance app.  The app appears to be worthwhile in this scenario:  "Now that we have logged &lt;EM&gt;everything&lt;/EM&gt; in Splunk, use the app determine overall compliance and gaps".   But we're not interested in logging everything to Splunk.  Instead we're curious to hear best practices regarding what is valuable to log in Splunk (i.e. Splunk is the best place for it because Splunk adds value in meeting PCI DSS audit/storage requirements) versus what is not valuable in Splunk (i.e., don't waste your ingestion license because Splunk adds no value in helping to meet PCI DSS audit/storage requirements).  Any thoughts on this topic are greatly appreciated. &lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 17:40:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-optimize-Splunk-for-PCI-Compliance/m-p/324634#M2980</guid>
      <dc:creator>JimSchlaker</dc:creator>
      <dc:date>2017-09-06T17:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to optimize Splunk for PCI Compliance?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-optimize-Splunk-for-PCI-Compliance/m-p/324635#M2981</link>
      <description>&lt;P&gt;You don't have to use the PCI Compliance app, but it can give ideas about how Splunk can help monitor compliance.  See what indicators the app provides, decide which ones are important to you, then log the data needed for those indicators.  You can even build your own dashboard(s) using that data.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2017 19:29:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-optimize-Splunk-for-PCI-Compliance/m-p/324635#M2981</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2017-09-06T19:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to optimize Splunk for PCI Compliance?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-optimize-Splunk-for-PCI-Compliance/m-p/324636#M2982</link>
      <description>&lt;P&gt;I want to do pci  but not through app, can you tell me what are best practices in Splunk to make logs pci compliance .&lt;/P&gt;</description>
      <pubDate>Fri, 21 Dec 2018 19:26:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-optimize-Splunk-for-PCI-Compliance/m-p/324636#M2982</guid>
      <dc:creator>rajneeshc1981</dc:creator>
      <dc:date>2018-12-21T19:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to optimize Splunk for PCI Compliance?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/How-to-optimize-Splunk-for-PCI-Compliance/m-p/324637#M2983</link>
      <description>&lt;P&gt;The PCI Compliance App is far from free; several hundred thousand dollars. &lt;/P&gt;</description>
      <pubDate>Wed, 08 Apr 2020 14:11:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/How-to-optimize-Splunk-for-PCI-Compliance/m-p/324637#M2983</guid>
      <dc:creator>cly</dc:creator>
      <dc:date>2020-04-08T14:11:30Z</dc:date>
    </item>
  </channel>
</rss>

