Security

Are there any new resources on Splunk On Prem Data Integrity and Anti Tamper Controls?

NightShark
Path Finder

Hello,

I have looked over blogs and topics being discussed about Splunk's Data Integrity Checks and Anti Tampering controls, yet most of the resources found were outdated and/or not found anymore.

Are there any new sources or apps that keep track of Splunk's own security from its Admins via the configuration tracker index or other means?

Thanks,
Best Regards,

Labels (1)
0 Karma
1 Solution

VatsalJagani
SplunkTrust
SplunkTrust

@NightShark - For the 1st item I know you (as a admin user) will see a message on the Splunk screen as shown here in the screenshot, that's where you will see that message.

VatsalJagani_0-1692619827732.png

 

View solution in original post

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@NightShark - Splunk has two things for it:

  1. Splunk gives error for file hash not matching if it finds files being updated/deleted which not suppose to change.
  2. It has a configuration changes tracker. Search for index=_configtracker

 

I hope this helps!!!

0 Karma

NightShark
Path Finder

Hello @VatsalJagani,

Thank you for your response, what is that feature called about giving an alert when hashes do not match?

Second of all, is there a list of specific configuration changes that could allow us to tamper with the data before being sent to the indexers like sed being added for example in the configuration files?

Thanks,

Regards,

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@NightShark - For the 1st item I know you (as a admin user) will see a message on the Splunk screen as shown here in the screenshot, that's where you will see that message.

VatsalJagani_0-1692619827732.png

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Design, Compete, Win: Submit Your Best Splunk Dashboards for a .conf26 Pass

Hello Splunkers,  We’re excited to kick off a Splunk Dashboard contest! We know that dashboards are a primary ...

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...