<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Missing Audit logs in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-we-Missing-Audit-logs/m-p/553613#M5033</link>
    <description>&lt;P&gt;Did you manage to find the solution as to why the login activity is not showing up in Splunk 8.X?&lt;/P&gt;</description>
    <pubDate>Sat, 29 May 2021 06:53:04 GMT</pubDate>
    <dc:creator>CyberWarrior404</dc:creator>
    <dc:date>2021-05-29T06:53:04Z</dc:date>
    <item>
      <title>Why are we Missing Audit logs?</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-we-Missing-Audit-logs/m-p/495143#M4102</link>
      <description>&lt;P&gt;I just noticed that our Redhat splunk servers are missing audit log data for users logging in to Splunk.&lt;/P&gt;
&lt;P&gt;For example, this query no longer returns data:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;index=_audit action="login attempt" "info=succeeded"&lt;/LI-CODE&gt;
&lt;P&gt;I do have some audit data, just not the login attempts.&lt;/P&gt;
&lt;P&gt;The data seems to of stopped after upgrading to version &amp;gt;=8.0.0&lt;/P&gt;
&lt;P&gt;I only have one windows splunk server, and ALL the audit data appears to be there.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 15:38:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-we-Missing-Audit-logs/m-p/495143#M4102</guid>
      <dc:creator>RDAVISS</dc:creator>
      <dc:date>2022-04-27T15:38:27Z</dc:date>
    </item>
    <item>
      <title>Re: Missing Audit logs</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-we-Missing-Audit-logs/m-p/495144#M4103</link>
      <description>&lt;P&gt;Sounds like your search heads are no longer forwarding internal logs to the indexer cluster.&lt;BR /&gt;
Ensure they are configured to do so by examining $SPLUNK_HOME/etc/system/local/outputs.conf to verify the SHC is sending those logs to the indexers. And/or look at inputs.conf to verify there are no blacklists that might be blocking those logs.&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.2/Admin/Outputsconf#outputs.conf.example"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.2/Admin/Outputsconf#outputs.conf.example&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Mar 2020 22:49:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-we-Missing-Audit-logs/m-p/495144#M4103</guid>
      <dc:creator>codebuilder</dc:creator>
      <dc:date>2020-03-16T22:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: Missing Audit logs</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-we-Missing-Audit-logs/m-p/495145#M4104</link>
      <description>&lt;P&gt;We double-checked the outputs and don't see any errors. The indexer is getting some events (e.g failed logins are showing up, just not the successful logins. )&lt;/P&gt;

&lt;P&gt;I will take a look at the inputs again just to make sure there are no problems with our blacklisting. &lt;/P&gt;

&lt;P&gt;What's strange is the  successful events aren't actually on the local search heads logs &lt;BR /&gt;
(/$SPLUNK_HOME/var/splunk/log/audit.log)&lt;/P&gt;

&lt;P&gt;That's why I leaning towards a change in functionality with the 8.0 release.&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2020 16:41:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-we-Missing-Audit-logs/m-p/495145#M4104</guid>
      <dc:creator>RDAVISS</dc:creator>
      <dc:date>2020-03-26T16:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: Missing Audit logs</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-we-Missing-Audit-logs/m-p/495146#M4105</link>
      <description>&lt;P&gt;I engaged splunk support and there was a code change around version 8.x that might have caused this to stop working. &lt;/P&gt;

&lt;P&gt;Once I have a workaround I will post it here. &lt;/P&gt;</description>
      <pubDate>Fri, 03 Apr 2020 14:36:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-we-Missing-Audit-logs/m-p/495146#M4105</guid>
      <dc:creator>RDAVISS</dc:creator>
      <dc:date>2020-04-03T14:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: Missing Audit logs</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-we-Missing-Audit-logs/m-p/553613#M5033</link>
      <description>&lt;P&gt;Did you manage to find the solution as to why the login activity is not showing up in Splunk 8.X?&lt;/P&gt;</description>
      <pubDate>Sat, 29 May 2021 06:53:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-we-Missing-Audit-logs/m-p/553613#M5033</guid>
      <dc:creator>CyberWarrior404</dc:creator>
      <dc:date>2021-05-29T06:53:04Z</dc:date>
    </item>
    <item>
      <title>Re: Missing Audit logs</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-we-Missing-Audit-logs/m-p/553638#M5036</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;at least all in one node with 8.2.0 the event is still the same&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Audit:[timestamp=05-29-2021 23:06:55.778, user=XXXXX, action=login attempt, info=succeeded reason=user-initiated useragent="Mozilla/5.0 (XXX; XXX ) XXXXX/....." clientip=127.0.0.1" method=Splunk" session=ecd9cadalsdklakdlakd8d5391718ea8]&lt;/LI-CODE&gt;&lt;P&gt;I haven't access to distributed environment to check it (only 8.x.x).&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index = _audit sourcetype=audittrail action="login attempt" info=*
| stats count by user,info&lt;/LI-CODE&gt;&lt;P&gt;Previous example founds users as expected.&lt;/P&gt;&lt;P&gt;r. Ismo&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 29 May 2021 20:16:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-we-Missing-Audit-logs/m-p/553638#M5036</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-05-29T20:16:26Z</dc:date>
    </item>
    <item>
      <title>Re: Missing Audit logs</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-we-Missing-Audit-logs/m-p/595589#M8930</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/158941"&gt;@RDAVISS&lt;/a&gt;&amp;nbsp;That search doesn't work if you have the Splunk_SA_CIM installed because "action" will never equal "login attempt"&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[audittrail]
EVAL-action = case(match(_raw,"action\=login\sattempt") AND match(_raw,"info\=succeeded"),"success",match(_raw,"action\=login\sattempt") AND match(_raw,"info\=failed"),"failure",match(_raw,"action\=add"),"created",match(_raw,"action\=delete"),"deleted",match(_raw,"action\=update"),"modified",1=1,action)
EVAL-app = if(match(_raw,"action\=login\sattempt"),"splunk",app)&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;Try it without action=&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_audit "login attempt" "info=succeeded"&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 13:53:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Why-are-we-Missing-Audit-logs/m-p/595589#M8930</guid>
      <dc:creator>dfronck</dc:creator>
      <dc:date>2022-04-27T13:53:34Z</dc:date>
    </item>
  </channel>
</rss>

