<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic splunk client ssh in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/splunk-client-ssh/m-p/550288#M5002</link>
    <description>&lt;P&gt;I have installed CentOS 7 on a EC2 server and on CentOS 7 Installed splunk and universal forwarding.&amp;nbsp; Now I need help with how&amp;nbsp;&lt;SPAN&gt;to store client ssh login and logoff record?.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 03 May 2021 22:24:54 GMT</pubDate>
    <dc:creator>obadr56</dc:creator>
    <dc:date>2021-05-03T22:24:54Z</dc:date>
    <item>
      <title>splunk client ssh</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/splunk-client-ssh/m-p/550288#M5002</link>
      <description>&lt;P&gt;I have installed CentOS 7 on a EC2 server and on CentOS 7 Installed splunk and universal forwarding.&amp;nbsp; Now I need help with how&amp;nbsp;&lt;SPAN&gt;to store client ssh login and logoff record?.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 22:24:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/splunk-client-ssh/m-p/550288#M5002</guid>
      <dc:creator>obadr56</dc:creator>
      <dc:date>2021-05-03T22:24:54Z</dc:date>
    </item>
    <item>
      <title>Re: splunk client ssh</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/splunk-client-ssh/m-p/550295#M5003</link>
      <description>&lt;P&gt;First, there's rarely a need to install Splunk and a universal forwarder on the same server.&amp;nbsp; Install one or the other.&lt;/P&gt;&lt;P&gt;Second, please describe your use case in more detail.&amp;nbsp; What problem are you trying to solve?&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 23:14:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/splunk-client-ssh/m-p/550295#M5003</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-05-03T23:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: splunk client ssh</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/splunk-client-ssh/m-p/550296#M5004</link>
      <description>&lt;P&gt;I am trying to setup splunk so it can&amp;nbsp;&lt;SPAN&gt;store client ssh login and logoff record how do I do that with splunk?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 23:19:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/splunk-client-ssh/m-p/550296#M5004</guid>
      <dc:creator>obadr56</dc:creator>
      <dc:date>2021-05-03T23:19:41Z</dc:date>
    </item>
    <item>
      <title>Re: splunk client ssh</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/splunk-client-ssh/m-p/550297#M5005</link>
      <description>&lt;P&gt;So what do I have to do to have&amp;nbsp;&lt;STRONG&gt;&lt;SPAN&gt;splunk to store client ssh login and logoff record on my ec2 instance with centos 7 installed do I have to remove universal forwarding and install it on another ec2 please help and advise.&amp;nbsp; I am new to Splunk so be patient with me thanks a lot for helping.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 03 May 2021 23:38:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/splunk-client-ssh/m-p/550297#M5005</guid>
      <dc:creator>obadr56</dc:creator>
      <dc:date>2021-05-03T23:38:11Z</dc:date>
    </item>
    <item>
      <title>Re: splunk client ssh</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/splunk-client-ssh/m-p/550388#M5006</link>
      <description>&lt;P&gt;Use Splunk or the UF to monitor /var/log/audit/audit.log on each EC2 instance.&amp;nbsp; Do that by adding a monitor stanza to the inputs.conf file on each instance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;You will need to use SELinux or SETFACL to give Splunk (or the UF) permission to read the file.&lt;/P&gt;</description>
      <pubDate>Tue, 04 May 2021 12:15:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/splunk-client-ssh/m-p/550388#M5006</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-05-04T12:15:33Z</dc:date>
    </item>
    <item>
      <title>Re: splunk client ssh</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/splunk-client-ssh/m-p/564410#M8543</link>
      <description>&lt;P&gt;It sounds like you want to monitor on CentOS7: `/var/log/secure` as that file has all the entries for SSH sessions.&lt;/P&gt;&lt;P&gt;To make things less complicated: run the SUF as `root`, it will be easier to understand how things work. You can test on an isolated EC2 instance and secure later.&lt;/P&gt;&lt;P&gt;If you want to forward `/var/log/secure` from other EC2 instances to your indexer, those will only require a SUF installed.&lt;/P&gt;&lt;P&gt;You do not need a SUF and indexer installed on the same host. If you have installed Splunk proper, with web and all you can add a monitor input for `/var/log/secure`.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 19:01:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/splunk-client-ssh/m-p/564410#M8543</guid>
      <dc:creator>ephemeric</dc:creator>
      <dc:date>2021-08-23T19:01:31Z</dc:date>
    </item>
  </channel>
</rss>

