Data integrity controls in Splunk ensure that indexed data has not been tampered with.
When enabled, Splunk calculates hashes for each bucket and stores these hash files in the rawdata directory of the corresponding bucket.
Incorrect Options:
A, C, D: These directories do not store hash files.
References:
Splunk Docs: Configure data integrity controls
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit