# Checking for tampering of indices

**URL:** <https://discuss.elastic.co/t/checking-for-tampering-of-indices/20031>\
**Category:** Elasticsearch\
**Created:** [October 1, 2014, 7:20pm UTC](https://discuss.elastic.co/t/checking-for-tampering-of-indices/20031 "2014-10-01T19:20:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Brian\_Wilkins](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/brian_wilkins/32/1241_2.png) [@Brian\_Wilkins](https://discuss.elastic.co/u/Brian_Wilkins)\
**Post date:** [October 1, 2014, 7:20pm UTC](https://discuss.elastic.co/t/checking-for-tampering-of-indices/20031/1 "2014-10-01T19:20:27Z")

</div>

In Splunk, it is possible to detect tampering of logs. Splunk will take an  
event at ingestion time and create a hash value based on the event and your  
certificates/keys. You can then write searches that will re-hash the event  
to be compared to the original to indicate if anything has changed. We  
need something like that.

How is that possible with elasticsearch?

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/3b724745-88ac-4484-9d21-284ec28697a9%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/3b724745-88ac-4484-9d21-284ec28697a9%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 1, 2014, 9:14pm UTC](https://discuss.elastic.co/t/checking-for-tampering-of-indices/20031/2 "2014-10-01T21:14:56Z")

</div>

You might be able to achieve this with versioning -

> **[Elasticsearch Platform — Find real-time answers at scale](https://www.elastic.co)**
>
> Power insights and outcomes with the Elasticsearch Platform and AI. See into your data and find answers that matter with enterprise solutions designed to help you build, observe, and protect. Try Elasticsearch free today.

Regards,  
Mark Walkom

Infrastructure Engineer  
Campaign Monitor  
email: [markw@campaignmonitor.com](mailto:markw@campaignmonitor.com)  
web: [www.campaignmonitor.com](http://www.campaignmonitor.com)

On 2 October 2014 05:20, Brian Wilkins [bwilkins@gmail.com](mailto:bwilkins@gmail.com) wrote:

> In Splunk, it is possible to detect tampering of logs. Splunk will take  
> an event at ingestion time and create a hash value based on the event and  
> your certificates/keys. You can then write searches that will re-hash the  
> event to be compared to the original to indicate if anything has changed.  
> We need something like that.
> 
> How is that possible with elasticsearch?
> 
> --  
> You received this message because you are subscribed to the Google Groups  
> "elasticsearch" group.  
> To unsubscribe from this group and stop receiving emails from it, send an  
> email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
> To view this discussion on the web visit  
> [https://groups.google.com/d/msgid/elasticsearch/3b724745-88ac-4484-9d21-284ec28697a9%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/3b724745-88ac-4484-9d21-284ec28697a9%40googlegroups.com)  
> [https://groups.google.com/d/msgid/elasticsearch/3b724745-88ac-4484-9d21-284ec28697a9%40googlegroups.com?utm\_medium=email&utm\_source=footer](https://groups.google.com/d/msgid/elasticsearch/3b724745-88ac-4484-9d21-284ec28697a9%40googlegroups.com?utm_medium=email&utm_source=footer)  
> .  
> For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/CAEM624Y2mu13pfoQRvcEngY%3DZ3JvXNqrT%2Bc05q3HV3EaOZmrtg%40mail.gmail.com](https://groups.google.com/d/msgid/elasticsearch/CAEM624Y2mu13pfoQRvcEngY%3DZ3JvXNqrT%2Bc05q3HV3EaOZmrtg%40mail.gmail.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:58am UTC](https://discuss.elastic.co/t/checking-for-tampering-of-indices/20031/3 "2017-07-06T00:58:51Z")

</div>


