Quantcast
Viewing all articles
Browse latest Browse all 47296

Event ID for each event in the index

Hi My auditors are questioning and requiring that each event we log into splunk has a unique identifier added by Splunk I see where they are coming from but cannot produce evidence of something I know intuitively to be true. Splunk must maintain an internal index of events to enable the searching to work so each recorded event must have a unique id from that . I just need to evidence it for the Auditors

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>