<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Query information in Security</title>
    <link>https://community.splunk.com/t5/Security/Query-information/m-p/578448#M15772</link>
    <description>&lt;P&gt;To me, it doesn't look like there is anything in the event that identifies which server is sending the syslog file to the proxy server. Unless you can see something?&lt;/P&gt;</description>
    <pubDate>Wed, 15 Dec 2021 11:43:47 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2021-12-15T11:43:47Z</dc:date>
    <item>
      <title>Query information</title>
      <link>https://community.splunk.com/t5/Security/Query-information/m-p/578393#M15769</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a UNIX server Solaris 8 that ac/behave like a Splunk Proxy server for 2 other UNIX servers Solaris 8.&lt;/P&gt;&lt;P&gt;In other words the 2 Solaris servers send the syslog file to the UNIX Solaris Proxy server.&lt;/P&gt;&lt;P&gt;I am trying to create a query that will shows the events coming from the 2 UNIX Solaris 8 servers.&lt;/P&gt;&lt;P&gt;I run the below query for example:&lt;/P&gt;&lt;P&gt;index=nix* serverproxy*&lt;BR /&gt;| eval Status=if(like(source, "%FirstUNIXSolaris8%"), 1, 0)&lt;/P&gt;&lt;P&gt;I am not getting any event that will show the FirstUNIX Solaris8 name/hostname.&lt;/P&gt;&lt;P&gt;Please any suggestion how to create the specific query ?&lt;/P&gt;&lt;P&gt;Thanks, Regards.&lt;/P&gt;&lt;P&gt;Roberto&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 23:13:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Query-information/m-p/578393#M15769</guid>
      <dc:creator>rballan2</dc:creator>
      <dc:date>2021-12-14T23:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: Query information</title>
      <link>https://community.splunk.com/t5/Security/Query-information/m-p/578397#M15770</link>
      <description>&lt;P&gt;What do your events look like once they are indexed in splunk? Presumably, host is the proxy server and source is the syslog file? What other fields have been extracted?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 23:24:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Query-information/m-p/578397#M15770</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-12-14T23:24:49Z</dc:date>
    </item>
    <item>
      <title>Re: Query information</title>
      <link>https://community.splunk.com/t5/Security/Query-information/m-p/578443#M15771</link>
      <description>&lt;P&gt;Below is an example of Event when I run the query:&amp;nbsp; index=nix* Proxyservername*&lt;/P&gt;&lt;P&gt;Source is /var/adm/messages and /var/log/secure (UNIX LOGS).&lt;/P&gt;&lt;P&gt;Selected fields are:&lt;/P&gt;&lt;P&gt;host&lt;/P&gt;&lt;P&gt;index&lt;/P&gt;&lt;P&gt;process&lt;/P&gt;&lt;P&gt;source&lt;/P&gt;&lt;P&gt;sourcetype&lt;/P&gt;&lt;P&gt;tag&lt;/P&gt;&lt;P&gt;********************************************&lt;/P&gt;&lt;P&gt;12/13/21&lt;BR /&gt;6:15:01.000 AM Column icon&lt;/P&gt;&lt;P&gt;Dec 13 01:15:01 PROXYserver CROND[15913]: (flaradm) CMD (cd /vol00/ServerMgmt/Deploy_script/CURRENT/utils/UvScan_DATs/ ; scp *.dat root@PROXYservr:/usr/local/uvscan/ )&lt;/P&gt;&lt;P&gt;host = Proxyserver&lt;BR /&gt;index = nixlogsec&lt;BR /&gt;process = CROND&lt;BR /&gt;source = /var/log/messages&lt;BR /&gt;sourcetype = syslog&lt;/P&gt;&lt;P&gt;›&lt;BR /&gt;12/13/21&lt;BR /&gt;6:15:01.000 AM Column icon&lt;/P&gt;&lt;P&gt;Dec 13 01:15:01 PROXYserver CROND[15913]: (flaradm) CMD (cd /vol00/ServerMgmt/Deploy_script/CURRENT/utils/UvScan_DATs/ ; scp *.dat root@PROXYservr:/usr/local/uvscan/ )&lt;/P&gt;&lt;P&gt;host = Proxyserver&lt;BR /&gt;index = nixlogsec&lt;BR /&gt;process = CROND&lt;BR /&gt;source = /var/log/secure&lt;BR /&gt;sourcetype = linux_secure&lt;BR /&gt;tag = os tag = unix&lt;/P&gt;&lt;P&gt;›&lt;BR /&gt;12/12/21&lt;BR /&gt;1:31:33.000 PM Column icon&lt;/P&gt;&lt;P&gt;Dec 12 08:31:33 PROXYserver root: [ID 702911 local1.info] ITSEC : UVSCAN : [uvscan check failed]&lt;/P&gt;&lt;P&gt;host = PROXYservr.lmtas.com&lt;BR /&gt;index = nixlogsec&lt;BR /&gt;process = root&lt;BR /&gt;source = /var/adm/messages&lt;BR /&gt;sourcetype = syslog&lt;BR /&gt;tag = error&lt;/P&gt;&lt;P&gt;›&lt;BR /&gt;12/10/21&lt;BR /&gt;9:44:31.000 PM Column icon&lt;/P&gt;&lt;P&gt;Dec 10 16:44:31 PROXYserver scsi: [ID 107833 kern.notice] ASC: 0x32 (no defect spare location available), ASCQ: 0x0, FRU: 0x9d&lt;/P&gt;&lt;P&gt;host = PROXYservr.lmtas.com&lt;BR /&gt;index = nixlogsec&lt;BR /&gt;process = scsi&lt;BR /&gt;source = /var/adm/messages&lt;BR /&gt;sourcetype = syslog&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 10:42:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Query-information/m-p/578443#M15771</guid>
      <dc:creator>rballan2</dc:creator>
      <dc:date>2021-12-15T10:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: Query information</title>
      <link>https://community.splunk.com/t5/Security/Query-information/m-p/578448#M15772</link>
      <description>&lt;P&gt;To me, it doesn't look like there is anything in the event that identifies which server is sending the syslog file to the proxy server. Unless you can see something?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 11:43:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Query-information/m-p/578448#M15772</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2021-12-15T11:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: Query information</title>
      <link>https://community.splunk.com/t5/Security/Query-information/m-p/578450#M15773</link>
      <description>&lt;P&gt;You are correct, I do not see it either.&lt;/P&gt;&lt;P&gt;We are checking/verifying why we do not see any information that identifies which server (there are 2&lt;/P&gt;&lt;P&gt;UNIX server that are sending data to the Proxy server) is sending the syslog file to the proxy server.&lt;/P&gt;&lt;P&gt;I will update the "query"/messages&amp;nbsp; as soon as I have the information.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 11:53:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Query-information/m-p/578450#M15773</guid>
      <dc:creator>rballan2</dc:creator>
      <dc:date>2021-12-15T11:53:05Z</dc:date>
    </item>
  </channel>
</rss>

