Splunk Enterprise

Where do I find documentation reg. how long Splunk is retaining audit logs? Thank u

SamHTexas
Builder

Where do I find documentation reg. how long Splunk is retaining audit logs? Can this be edited? Thank u.

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The retention settings for the _audit index (assuming that is what is meant by "audit logs") are in an indexes.conf file ($SPLUNK_HOME/etc/system/default, by default).  You should be able to show the auditor a screenshot of the Settings->Indexes page showing the oldest entry in the index (if you have at least a year of data, of course).

richgalloway_0-1619535347139.png

 

---
If this reply helps you, Karma would be appreciated.
0 Karma

SamHTexas
Builder

Thank u sir, which server should I look this up on? Can it be done via GUI?

 

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

You can do it on any server with the full list of indexes.  Yes, it can be done using the GUI (as per the screenshot).

---
If this reply helps you, Karma would be appreciated.
0 Karma

SamHTexas
Builder

I looked this up the _audit index says Earliest event 5 month ago & latest event 4 month ago. Rich should this setting be changes in _audit & _internal indexes or just in _audit index please? This timing of 1 year log detention in the indexs.conf has to be done via CLI correct?

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Perhaps what you should do is sign in to one of the indexers and use btool to view the retention settings.

splunk btool indexes list _audit | grep frozenTimePeriodInSecs

The value will be in seconds so you'll have to do some math to convert it into days for the auditor.

---
If this reply helps you, Karma would be appreciated.

SamHTexas
Builder

Rich sir, I copy & pasted it into a SH but received unknown command. Please advise.

splunk btool indexes list _audit | grep frozenTimePeriodInSecs
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's a CLI command, not an SPL query.

---
If this reply helps you, Karma would be appreciated.

SamHTexas
Builder

I used it accessing the SH via CLI. Must have mistyped. Thank u. I will try again.

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

You may need to fully qualify the command.

/opt/splunk/bin/splunk btool indexes list _audit | grep frozenTimePeriodInSecs
---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...