audit event

noun

An event that Splunk has saved into the audit index. Every user interaction with Splunk--searches, configuration changes, event type creation--generates an audit event. Directories monitored by file system change monitoring create audit events as well.

If you are using Splunk with an Enterprise license you can configure Splunk to cryptographically sign audit events. This practice is called audit event signing. Audit event signing makes it easier for you to discover whether your data has been tampered with.

For more information

In the Admin Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time