Knowledge Management

Is it possible to modify an indexed event?

charlescywong
New Member

Is it possible to modify an indexed event? My company is using Splunk for detecting suspicious activities. One of the scenarios is to detect Failed Logons to servers. I am afraid that someone (e.g. attacker) can modify the timestamp, username, or even delete the whole log to cover his/her track. Anyone know about this?

Any white paper or official document has been released regarding to the above question?

Thanks in advance!

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Data indexed in Splunk cannot be changed. That doesn't mean the source log can't be modified before it is indexed, however.
It's possible to delete data in Splunk (it's actually just marked as "invisible") by someone with the 'can_delete' privilege, but that's easily avoided by not granting the privilege to anyone.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Data indexed in Splunk cannot be changed. That doesn't mean the source log can't be modified before it is indexed, however.
It's possible to delete data in Splunk (it's actually just marked as "invisible") by someone with the 'can_delete' privilege, but that's easily avoided by not granting the privilege to anyone.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...

Splunk Life | Happy Pride Month!

Happy Pride Month, Splunk Community! 🌈 In the United States, as well as many countries around the ...

SplunkTrust | Where Are They Now - Michael Uschmann

The Background Five years ago, Splunk published several videos showcasing members of the SplunkTrust to share ...