Information
Without non-repudiation, it is impossible to positively attribute an action to an individual (or process acting on behalf of an individual).
The records stored by Splunk Enterprise must be protected against alteration. A hash is one way of performing this function. The server must not allow the removal of identifiers or date/time, or it must severely restrict the ability to do so.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
If the server does not store index data, this fix is N/A.
Edit the following file in the installation folder:
$SPLUNK_HOME/etc/system/local/indexes.conf
Add the following line to each organization-defined index stanza in brackets [ ]:
enableDataIntegrityControl=true