Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Event ID for each event in the index

$
0
0
Hi My auditors are questioning and requiring that each event we log into splunk has a unique identifier added by Splunk I see where they are coming from but cannot produce evidence of something I know intuitively to be true. Splunk must maintain an internal index of events to enable the searching to work so each recorded event must have a unique id from that . I just need to evidence it for the Auditors

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>