<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Checking data integrity with search command in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Checking-data-integrity-with-search-command/m-p/145871#M40697</link>
    <description>&lt;P&gt;I'm looking for an answer to this issue as well.  Integrity can be checked "on demand", but that really isn't enough for policy compliance, we need to be able to actively monitor for changes.&lt;/P&gt;

&lt;P&gt;For your question, I though I read that you cannot check it at an index level.&lt;/P&gt;

&lt;P&gt;If splunk expects companies to rely on it for the entire log solution, there needs to be a solution to this.&lt;/P&gt;</description>
    <pubDate>Fri, 29 Nov 2013 13:17:22 GMT</pubDate>
    <dc:creator>hopnscotch</dc:creator>
    <dc:date>2013-11-29T13:17:22Z</dc:date>
    <item>
      <title>Checking data integrity with search command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Checking-data-integrity-with-search-command/m-p/145870#M40696</link>
      <description>&lt;P&gt;A short question:&lt;/P&gt;

&lt;P&gt;I have configured IT data block signing, as described here:&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0/Security/ITDataSigning"&gt;http://docs.splunk.com/Documentation/Splunk/6.0/Security/ITDataSigning&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Checking the integrity via "Show Source" in SplunkWeb works fine, but is there a way to verify the integrity with a search command (so I can perform the check via API, etc.).&lt;/P&gt;

&lt;P&gt;Example: I want an output as the following SPL-Statement gives me, if audit event signing is enabled.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_audit | audit | table validity gap _raw
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 18 Nov 2013 09:55:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Checking-data-integrity-with-search-command/m-p/145870#M40696</guid>
      <dc:creator>hRun</dc:creator>
      <dc:date>2013-11-18T09:55:11Z</dc:date>
    </item>
    <item>
      <title>Re: Checking data integrity with search command</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Checking-data-integrity-with-search-command/m-p/145871#M40697</link>
      <description>&lt;P&gt;I'm looking for an answer to this issue as well.  Integrity can be checked "on demand", but that really isn't enough for policy compliance, we need to be able to actively monitor for changes.&lt;/P&gt;

&lt;P&gt;For your question, I though I read that you cannot check it at an index level.&lt;/P&gt;

&lt;P&gt;If splunk expects companies to rely on it for the entire log solution, there needs to be a solution to this.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Nov 2013 13:17:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Checking-data-integrity-with-search-command/m-p/145871#M40697</guid>
      <dc:creator>hopnscotch</dc:creator>
      <dc:date>2013-11-29T13:17:22Z</dc:date>
    </item>
  </channel>
</rss>

