Hi My auditors are questioning and requiring that each event we log into splunk has a unique identifier added by Splunk I see where they are coming from but cannot produce evidence of something I know intuitively to be true. Splunk must maintain an internal index of events to enable the searching to work so each recorded event must have a unique id from that . I just need to evidence it for the Auditors
↧