Archive
Highlighted

What has replaced event signing (event hashing) in Splunk 6.3.2?

Explorer

I have been using event hashing since we installed Splunk several years ago. On upgrade to Splunk 6.3.2 today, I am now informed that the event signing feature is no longer available. Neither is block signing.

What should I be using now?

Highlighted

Re: What has replaced event signing (event hashing) in Splunk 6.3.2?

SplunkTrust
SplunkTrust

Data Integrity is the new feature that can replace event hashing: http://blogs.splunk.com/2015/10/28/data-integrity-is-back-baby/

It's not a 1to1 replacement but it should do the trick in most cases.