Alerting

Monitoring Root Account on Linux Server

10061987
Engager

Hi all,

I have a case about monitoring Linux servers. Here what i am trying to do. I am not sure this is possible or not but i have to do these things with possibilities because System Staff wanted these from me.

1-Root SSH access enabled servers --> Need Help

2-When someone changed sudoers file --> Done.

3-Root password change --> Done.

4-Users who have "0" ID except root --> Need Help

 

I did some steps but i need help about 2 step. Any help would be appreciated!

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
what you already have in those servers?
- UF
- some Unix/Linux TAs
- what kind of data it is collection
- what logs it's collecting
- how and in which user your UF is running (shouldn't run as root).
r. Ismo
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...