Deployment Architecture

IT data signing

imacdonald2
Path Finder

The manual says

Block signing is not supported for distributed search.

I am wondering if I send data to multiple indexers, then ran the audit reports on each indexer rather than a search head, would IT data signing work?

jbsplunk
Splunk Employee
Splunk Employee

Yes, it would work under those conditions. But it would also be really expensive.

Get Updates on the Splunk Community!

Splunk MCP & Agentic AI: Machine Data Without Limits

  Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization ...

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...