Splunk Search

Checking data integrity with search command

hRun
Path Finder

A short question:

I have configured IT data block signing, as described here:http://docs.splunk.com/Documentation/Splunk/6.0/Security/ITDataSigning

Checking the integrity via "Show Source" in SplunkWeb works fine, but is there a way to verify the integrity with a search command (so I can perform the check via API, etc.).

Example: I want an output as the following SPL-Statement gives me, if audit event signing is enabled.

index=_audit | audit | table validity gap _raw
0 Karma

hopnscotch
Path Finder

I'm looking for an answer to this issue as well. Integrity can be checked "on demand", but that really isn't enough for policy compliance, we need to be able to actively monitor for changes.

For your question, I though I read that you cannot check it at an index level.

If splunk expects companies to rely on it for the entire log solution, there needs to be a solution to this.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

    Thursday, June 25, 2026  |  11AM PDT / 2PM EDT  Duration: 1 Hour (Includes live Q&A) Register to ...

Analytics Workspace deprecation

As of Splunk Cloud Platform 10.4.2604 and Splunk Enterprise 10.4, Analytics Workspace is now deprecated. ...

Splunk Developer Day Recap: Building, Publishing, and Growing on the Splunk Platform

Splunk Developer Day brought the Splunk developer community together for a practical look at what it means to ...