<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: auditd splunkd in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/auditd-splunkd/m-p/56415#M1885</link>
    <description>&lt;P&gt;Are these messages being generated from syscall rules or file system rules?  If you are using a syscall rule, you can use the -F switch and exclude the uid of the Splunk user.&lt;/P&gt;

&lt;P&gt;The other option is to just have Splunk route those events to the nullQueue.&lt;/P&gt;

&lt;P&gt;Craig&lt;/P&gt;</description>
    <pubDate>Sat, 09 Mar 2013 00:12:02 GMT</pubDate>
    <dc:creator>responsys_cm</dc:creator>
    <dc:date>2013-03-09T00:12:02Z</dc:date>
    <item>
      <title>auditd splunkd</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/auditd-splunkd/m-p/56414#M1884</link>
      <description>&lt;P&gt;We are required to monitor /var/log/audit. Whenever splunkd accesses audit.log a new event is created. We are getting close to ten thousand of these messages per hour. I have tried to create an excpetion in audit.rules, however there does not seem to be a good hook, that won't affect legitimate audit.log access events.  Any ideas how to solve this issue?&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2013 00:02:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/auditd-splunkd/m-p/56414#M1884</guid>
      <dc:creator>criscollins</dc:creator>
      <dc:date>2013-03-09T00:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: auditd splunkd</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/auditd-splunkd/m-p/56415#M1885</link>
      <description>&lt;P&gt;Are these messages being generated from syscall rules or file system rules?  If you are using a syscall rule, you can use the -F switch and exclude the uid of the Splunk user.&lt;/P&gt;

&lt;P&gt;The other option is to just have Splunk route those events to the nullQueue.&lt;/P&gt;

&lt;P&gt;Craig&lt;/P&gt;</description>
      <pubDate>Sat, 09 Mar 2013 00:12:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/auditd-splunkd/m-p/56415#M1885</guid>
      <dc:creator>responsys_cm</dc:creator>
      <dc:date>2013-03-09T00:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: auditd splunkd</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/auditd-splunkd/m-p/56416#M1886</link>
      <description>&lt;P&gt;splunk runs as root. &lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2016 19:44:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/auditd-splunkd/m-p/56416#M1886</guid>
      <dc:creator>tmacdonagh</dc:creator>
      <dc:date>2016-09-29T19:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: auditd splunkd</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/auditd-splunkd/m-p/56417#M1887</link>
      <description>&lt;P&gt;Removed my previous bad answer. The proper line to be entered into your audit.rules file is &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;-a exit,never  -F path=/opt/splunkforwarder/bin/splunkd -k splunk_exclude&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2016 21:23:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/auditd-splunkd/m-p/56417#M1887</guid>
      <dc:creator>tmacdonagh</dc:creator>
      <dc:date>2016-10-20T21:23:44Z</dc:date>
    </item>
  </channel>
</rss>

