Splunk Enterprise

Where do I find documentation reg. how long Splunk is retaining audit logs? Thank u

SamHTexas
Builder

Where do I find documentation reg. how long Splunk is retaining audit logs? Can this be edited? Thank u.

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The retention settings for the _audit index (assuming that is what is meant by "audit logs") are in an indexes.conf file ($SPLUNK_HOME/etc/system/default, by default).  You should be able to show the auditor a screenshot of the Settings->Indexes page showing the oldest entry in the index (if you have at least a year of data, of course).

richgalloway_0-1619535347139.png

 

---
If this reply helps you, an upvote would be appreciated.
0 Karma

SamHTexas
Builder

Thank u sir, which server should I look this up on? Can it be done via GUI?

 

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

You can do it on any server with the full list of indexes.  Yes, it can be done using the GUI (as per the screenshot).

---
If this reply helps you, an upvote would be appreciated.
0 Karma

SamHTexas
Builder

I looked this up the _audit index says Earliest event 5 month ago & latest event 4 month ago. Rich should this setting be changes in _audit & _internal indexes or just in _audit index please? This timing of 1 year log detention in the indexs.conf has to be done via CLI correct?

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Perhaps what you should do is sign in to one of the indexers and use btool to view the retention settings.

splunk btool indexes list _audit | grep frozenTimePeriodInSecs

The value will be in seconds so you'll have to do some math to convert it into days for the auditor.

---
If this reply helps you, an upvote would be appreciated.

SamHTexas
Builder

Rich sir, I copy & pasted it into a SH but received unknown command. Please advise.

splunk btool indexes list _audit | grep frozenTimePeriodInSecs
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's a CLI command, not an SPL query.

---
If this reply helps you, an upvote would be appreciated.

SamHTexas
Builder

I used it accessing the SH via CLI. Must have mistyped. Thank u. I will try again.

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

You may need to fully qualify the command.

/opt/splunk/bin/splunk btool indexes list _audit | grep frozenTimePeriodInSecs
---
If this reply helps you, an upvote would be appreciated.
0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!