<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk add-on for Fudo PAM | How to parse logs from Fudo? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-add-on-for-Fudo-PAM-How-to-parse-logs-from-Fudo/m-p/688020#M114601</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/267362"&gt;@splunky_diamond&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I am unsure if there are any apps/TAs available for Fudo PAM data. The best would be to write magic 8 props for parsing the data. You can find the relevant documentation links below:&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkdoeswithyourdata" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkdoeswithyourdata&lt;/A&gt;&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Overviewofeventprocessing" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Overviewofeventprocessing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Createsourcetypes" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Createsourcetypes&lt;/A&gt;&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&lt;A href="https://lantern.splunk.com/Splunk_Platform/Product_Tips/Data_Management/Configuring_new_source_types" target="_blank"&gt;https://lantern.splunk.com/Splunk_Platform/Product_Tips/Data_Management/Configuring_new_source_types&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Tejas.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;If the above solution helps, an upvote is appreciated.&lt;/P&gt;</description>
    <pubDate>Mon, 20 May 2024 13:01:34 GMT</pubDate>
    <dc:creator>tej57</dc:creator>
    <dc:date>2024-05-20T13:01:34Z</dc:date>
    <item>
      <title>Splunk add-on for Fudo PAM | How to parse logs from Fudo?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-add-on-for-Fudo-PAM-How-to-parse-logs-from-Fudo/m-p/687853#M114580</link>
      <description>&lt;P&gt;Hello splunkers!&lt;BR /&gt;&lt;BR /&gt;Has anyone had experience with getting data in Splunk from PAM (Privileged Access Management) systems? I want to do the integration of Splunk with Fudo PAM. Question of getting logs from Fudo to Splunk is not a problem at all, it's easily done over syslog. However, I don't know how to parse these logs. The syslog sourcetype doesn't properly parse the events, it misses a lot of useful information such as: users, processes, action done, accounts, basically almost everything except for the IP of the node and the timestamp of the event.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Does anyone know if there is a good add-on for parsing logs from Fudo PAM? Or any other good way how to parse its logs?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks for taking time reading and replying to my post &lt;span class="lia-unicode-emoji" title=":red_heart:"&gt;❤️&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2024 11:44:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-add-on-for-Fudo-PAM-How-to-parse-logs-from-Fudo/m-p/687853#M114580</guid>
      <dc:creator>splunky_diamond</dc:creator>
      <dc:date>2024-05-17T11:44:08Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk add-on for Fudo PAM | How to parse logs from Fudo?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-add-on-for-Fudo-PAM-How-to-parse-logs-from-Fudo/m-p/688020#M114601</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/267362"&gt;@splunky_diamond&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;I am unsure if there are any apps/TAs available for Fudo PAM data. The best would be to write magic 8 props for parsing the data. You can find the relevant documentation links below:&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkdoeswithyourdata" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkdoeswithyourdata&lt;/A&gt;&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Overviewofeventprocessing" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Overviewofeventprocessing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Createsourcetypes" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Createsourcetypes&lt;/A&gt;&lt;/P&gt;&lt;P&gt;-&amp;nbsp;&lt;A href="https://lantern.splunk.com/Splunk_Platform/Product_Tips/Data_Management/Configuring_new_source_types" target="_blank"&gt;https://lantern.splunk.com/Splunk_Platform/Product_Tips/Data_Management/Configuring_new_source_types&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks,&lt;BR /&gt;Tejas.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;If the above solution helps, an upvote is appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 20 May 2024 13:01:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-add-on-for-Fudo-PAM-How-to-parse-logs-from-Fudo/m-p/688020#M114601</guid>
      <dc:creator>tej57</dc:creator>
      <dc:date>2024-05-20T13:01:34Z</dc:date>
    </item>
  </channel>
</rss>

