Alerting

Monitoring Root Account on Linux Server

10061987
Engager

Hi all,

I have a case about monitoring Linux servers. Here what i am trying to do. I am not sure this is possible or not but i have to do these things with possibilities because System Staff wanted these from me.

1-Root SSH access enabled servers --> Need Help

2-When someone changed sudoers file --> Done.

3-Root password change --> Done.

4-Users who have "0" ID except root --> Need Help

 

I did some steps but i need help about 2 step. Any help would be appreciated!

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
what you already have in those servers?
- UF
- some Unix/Linux TAs
- what kind of data it is collection
- what logs it's collecting
- how and in which user your UF is running (shouldn't run as root).
r. Ismo
0 Karma
Get Updates on the Splunk Community!

Get Operational Insights Quickly with Natural Language on the Splunk Platform

In today’s fast-paced digital world, turning data into actionable insights is essential for success. With ...

What’s New in Splunk Observability Cloud – June 2025

What’s New in Splunk Observability Cloud – June 2025 We are excited to announce the latest enhancements to ...

Almost Too Eventful Assurance: Part 2

Work While You SleepBefore you can rely on any autonomous remediation measures, you need to close the loop ...