<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to read audit.log file in Dashboards &amp; Visualizations</title>
    <link>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185766#M11488</link>
    <description>&lt;P&gt;can you post the relevant monitor stanza from &lt;CODE&gt;$SPLUNK_HOME/bin/splunk cmd btool inputs list --debug&lt;/CODE&gt; ?&lt;/P&gt;</description>
    <pubDate>Fri, 22 Apr 2016 08:25:58 GMT</pubDate>
    <dc:creator>jplumsdaine22</dc:creator>
    <dc:date>2016-04-22T08:25:58Z</dc:date>
    <item>
      <title>Unable to read audit.log file</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185755#M11477</link>
      <description>&lt;P&gt;Splunk by default monitors /opt/splunk/var/log/splunk folder in Splunk Universal Forwarder.&lt;BR /&gt;
But I am not able to see "audit.log" file in Splunk Web.&lt;BR /&gt;
I am able to see the file when I execute list monitor command.&lt;/P&gt;

&lt;P&gt;Also I tried to monitor that file separately by putting a monitor statement in etc/apps folder.&lt;BR /&gt;
But still I'm not able to see that file in the Splunk Web.&lt;/P&gt;

&lt;P&gt;The monitor statements looks as below.&lt;/P&gt;

&lt;P&gt;[monitor:///opt/splunkforwarder/var/log/splunk/audit.log]&lt;BR /&gt;
disabled = false&lt;BR /&gt;
index = test_index&lt;BR /&gt;
sourcetype = test_audit_log&lt;/P&gt;

&lt;P&gt;Could you please help me in getting the audit.log file?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 16:07:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185755#M11477</guid>
      <dc:creator>premg</dc:creator>
      <dc:date>2020-09-28T16:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to read audit.log file</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185756#M11478</link>
      <description>&lt;P&gt;Hi premg,&lt;/P&gt;

&lt;P&gt;first make sure your &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.0.2/Forwarding/Routeandfilterdatad#Filter_data_by_target_index"&gt;internal logs are forwarded&lt;/A&gt; from the universal forwarder towards the indexer, this is only in Splunk 6 UF default for &lt;CODE&gt;_audit&lt;/CODE&gt;. If so you can search like this for the events on the indexer:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=_audit
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2014 09:42:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185756#M11478</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-03-13T09:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to read audit.log file</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185757#M11479</link>
      <description>&lt;P&gt;Thanks MuS. &lt;/P&gt;

&lt;P&gt;I have also tried with index=_audit. But no luck.&lt;/P&gt;

&lt;P&gt;Also I am able to see /opt/splunk/var/log/splunk/audit.log path in the list monitor. So I believe it is monitored.&lt;/P&gt;

&lt;P&gt;But not able to search.&lt;/P&gt;

&lt;P&gt;Do I need to change anything else?&lt;/P&gt;</description>
      <pubDate>Thu, 13 Mar 2014 10:34:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185757#M11479</guid>
      <dc:creator>premg</dc:creator>
      <dc:date>2014-03-13T10:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to read audit.log file</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185758#M11480</link>
      <description>&lt;P&gt;I am experiencing this same problem - I can see logfiles /opt/splunkforwarder/var/log/metrics.log and also splunkd.log being monitored - but not audit.log - can anyone suggest where to look for a solution please?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2016 09:45:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185758#M11480</guid>
      <dc:creator>vincenp2</dc:creator>
      <dc:date>2016-04-21T09:45:22Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to read audit.log file</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185759#M11481</link>
      <description>&lt;P&gt;Can you post the search you are using?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2016 12:33:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185759#M11481</guid>
      <dc:creator>jplumsdaine22</dc:creator>
      <dc:date>2016-04-21T12:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to read audit.log file</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185760#M11482</link>
      <description>&lt;P&gt;thanks for replying - the search I am using is &lt;BR /&gt;
index=_* host=*&lt;BR /&gt;
this returns some hosts producing audittrail events, these are splunk indexers and heavy forwarders using the full splunk deployment.&lt;/P&gt;

&lt;P&gt;All servers which have splunkforwarder deployed and reporting to the heavy forwarder produce events from metrics.log and splunkd.log, but not audit.log&lt;/P&gt;

&lt;P&gt;I hope this information helps - if you need more then please let me know&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2016 12:41:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185760#M11482</guid>
      <dc:creator>vincenp2</dc:creator>
      <dc:date>2016-04-21T12:41:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to read audit.log file</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185761#M11483</link>
      <description>&lt;P&gt;I seem to be failing miserably typing in the search I am using - here it is in words - hope it makes sense&lt;BR /&gt;
index equals underscore asterisk  host equals asterisk&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2016 12:50:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185761#M11483</guid>
      <dc:creator>vincenp2</dc:creator>
      <dc:date>2016-04-21T12:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to read audit.log file</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185762#M11484</link>
      <description>&lt;P&gt;Yeah its not that intuitive how to put code samples in here. &lt;/P&gt;

&lt;P&gt;Enter a new line and indent 4 spaces&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;like this
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 21 Apr 2016 13:40:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185762#M11484</guid>
      <dc:creator>jplumsdaine22</dc:creator>
      <dc:date>2016-04-21T13:40:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to read audit.log file</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185763#M11485</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;index=_* host=*
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 21 Apr 2016 13:53:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185763#M11485</guid>
      <dc:creator>vincenp2</dc:creator>
      <dc:date>2016-04-21T13:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to read audit.log file</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185764#M11486</link>
      <description>&lt;P&gt;@Mus - do the UF's actually generate audit events?&lt;/P&gt;

&lt;P&gt;@premg - is there actually data on the forwarder in /opt/splunk/var/log/splunk/audit.log ? I strongly suspect there is nothing there to actually be monitored&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2016 14:25:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185764#M11486</guid>
      <dc:creator>jplumsdaine22</dc:creator>
      <dc:date>2016-04-21T14:25:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to read audit.log file</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185765#M11487</link>
      <description>&lt;P&gt;granted there's not much but there is data there - mainly from when splunk is stopped / started, and when conf files have been modified &lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2016 14:36:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185765#M11487</guid>
      <dc:creator>vincenp2</dc:creator>
      <dc:date>2016-04-21T14:36:26Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to read audit.log file</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185766#M11488</link>
      <description>&lt;P&gt;can you post the relevant monitor stanza from &lt;CODE&gt;$SPLUNK_HOME/bin/splunk cmd btool inputs list --debug&lt;/CODE&gt; ?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2016 08:25:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185766#M11488</guid>
      <dc:creator>jplumsdaine22</dc:creator>
      <dc:date>2016-04-22T08:25:58Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to read audit.log file</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185767#M11489</link>
      <description>&lt;P&gt;apologies for the delay in responding - &lt;/P&gt;

&lt;P&gt;The btool output from servers NOT reporting /opt/splunk/var/log/splunk/audit.log events (SPLUNKFORWARDER v6.2.5 deployed) - show the following stanzas exist (note that metrics.log and splunkd.log ARE being reported):&lt;/P&gt;

&lt;P&gt;/opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/default/inputs.conf [monitor:////opt/splunkforwarder/var/log/splunk/splunkd.log]&lt;BR /&gt;
/opt/splunkforwarder/etc/system/default/inputs.conf                        [monitor:///opt/splunkforwarder/var/log/splunk]&lt;BR /&gt;
/opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/default/inputs.conf [monitor:///opt/splunkforwarder/var/log/splunk/metrics.log]&lt;/P&gt;

&lt;P&gt;I've also checked the output from the btool command on a server which IS reporting/opt/splunk/var/log/splunk/audit.log events (as well as metrics.log and splunkd.log) and the only stanza which relates is as below, but as this is in a default directory I am assuming (perhaps incorrectly) that this has no impact? note  SPLUNK v6.2.5 deployed &lt;/P&gt;

&lt;P&gt;/opt/splunk/etc/system/default/inputs.conf                             [monitor:///opt/splunk/var/log/splunk]&lt;/P&gt;

&lt;P&gt;ALL the stanzas above relate to files in 'default' directories, obviously correct me if I'm wrong but these shouldn't have any impact whatsoever should they?&lt;/P&gt;</description>
      <pubDate>Tue, 26 Apr 2016 07:58:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185767#M11489</guid>
      <dc:creator>vincenp2</dc:creator>
      <dc:date>2016-04-26T07:58:49Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to read audit.log file</title>
      <link>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185768#M11490</link>
      <description>&lt;P&gt;So just checked on a Splunk universal forwarder 6.4.0 on Linux and there is an &lt;CODE&gt;audit.log&lt;/CODE&gt; in &lt;CODE&gt;/opt/splunkforwarder/var/log/splunk/&lt;/CODE&gt; and it contains useful information. For example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;04-27-2016 08:30:40.226 +1200 INFO  AuditLogger - Audit:[timestamp=04-27-2016 08:30:40.226, user=n/a, action=update,path="/opt/splunkforwarder/etc/apps/splunk_TA_nix_local_log/bin", isdir=1, size=4096, gid=1001, uid=1001, modtime="Wed Apr 27 08:28:17 2016", mode="rwxrwxr-x", hash=, chgs="modtime "][n/a]
04-27-2016 08:30:40.330 +1200 INFO  AuditLogger - Audit:[timestamp=04-27-2016 08:30:40.330, user=n/a, action=update,path="/opt/splunkforwarder/etc/apps/splunk_TA_nix_local_log/bin/tests.sh", isdir=0, size=336, gid=1001, uid=1001, modtime="Wed Apr 27 08:28:17 2016", mode="rwxrwxr-x", hash=, chgs="modtime "][n/a]
04-27-2016 10:31:45.225 +1200 INFO  AuditLogger - Audit:[timestamp=04-27-2016 10:31:45.225, user=n/a, action=splunkShuttingDown, info=n/a][n/a]
04-27-2016 10:31:49.783 +1200 INFO  AuditLogger - Audit:[timestamp=04-27-2016 10:31:49.783, user=n/a, action=splunkStarting, info=n/a][n/a]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;But &lt;CODE&gt;audit.log&lt;/CODE&gt; is not added as monitor:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;/opt/splunkforwarder/etc/apps/Splunk_TA_nix/default/inputs.conf            [monitor:///Library/Logs]
/opt/splunkforwarder/etc/apps/Splunk_TA_nix/default/inputs.conf            [monitor:///etc]
/opt/splunkforwarder/etc/apps/Splunk_TA_nix/default/inputs.conf            [monitor:///home/.../.bash_history]
/opt/splunkforwarder/etc/system/default/inputs.conf                        [monitor:///opt/splunkforwarder/etc/splunk.version]
/opt/splunkforwarder/etc/system/default/inputs.conf                        [monitor:///opt/splunkforwarder/var/log/splunk]
/opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/default/inputs.conf [monitor:///opt/splunkforwarder/var/log/splunk/metrics.log]
/opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/default/inputs.conf [monitor:///opt/splunkforwarder/var/log/splunk/splunkd.log]
/opt/splunkforwarder/etc/apps/Splunk_TA_nix/default/inputs.conf            [monitor:///root/.bash_history]
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;So maybe this was changed somewhen down the road or it's a feature &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2016 02:07:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Dashboards-Visualizations/Unable-to-read-audit-log-file/m-p/185768#M11490</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2016-04-27T02:07:32Z</dc:date>
    </item>
  </channel>
</rss>

