<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Looking for solutions for Linux/Unix Auditing? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Looking-for-solutions-for-Linux-Unix-Auditing/m-p/634431#M108565</link>
    <description>&lt;P&gt;Fairly new Splunk user here looking for Linux auditing solutions.&amp;nbsp; I am running a disconnected version of Splunk Enterprise and thus cannot make use of the content pack which replaced the application and add-on according to SplunkBase.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am I still able to use the archived applications and add-on?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Realistically I am seeking a solution that would allow me to configure the universal forwarders I'm using to send the appropriate data so I can create queries via the linux_secure sourcetype.&lt;/P&gt;</description>
    <pubDate>Wed, 15 Mar 2023 16:24:30 GMT</pubDate>
    <dc:creator>kymenope</dc:creator>
    <dc:date>2023-03-15T16:24:30Z</dc:date>
    <item>
      <title>Looking for solutions for Linux/Unix Auditing?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Looking-for-solutions-for-Linux-Unix-Auditing/m-p/634431#M108565</link>
      <description>&lt;P&gt;Fairly new Splunk user here looking for Linux auditing solutions.&amp;nbsp; I am running a disconnected version of Splunk Enterprise and thus cannot make use of the content pack which replaced the application and add-on according to SplunkBase.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Am I still able to use the archived applications and add-on?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Realistically I am seeking a solution that would allow me to configure the universal forwarders I'm using to send the appropriate data so I can create queries via the linux_secure sourcetype.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Mar 2023 16:24:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Looking-for-solutions-for-Linux-Unix-Auditing/m-p/634431#M108565</guid>
      <dc:creator>kymenope</dc:creator>
      <dc:date>2023-03-15T16:24:30Z</dc:date>
    </item>
    <item>
      <title>Re: Looking for solutions for Linux/Unix Auditing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Looking-for-solutions-for-Linux-Unix-Auditing/m-p/634467#M108568</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I'm not sure if I understood right your question.&lt;/P&gt;&lt;P&gt;There is no need to be a connection between your instance and splunkbase. Just download those apps/TAs etc from it to your workstation and then transfer those with any usable way to your UF's, DS and/or Splunk enterprise instances. Then just install those as instructions said and start to use those.&lt;/P&gt;&lt;P&gt;That's the way how I do installation almost every time. I use that direct connection to splunkbase only on my test/demo etc. instances, never on production systems.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 21:00:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Looking-for-solutions-for-Linux-Unix-Auditing/m-p/634467#M108568</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2023-03-14T21:00:20Z</dc:date>
    </item>
  </channel>
</rss>

