All Apps and Add-ons

How to detect login failure followed by root password change in linux?

KSPriya
Explorer

Hello, fellow splunkers!

 

What I am trying to do is to detect a failed login attempts followed by root password change in linux with correlation search or datamodel search?

Labels (1)
Tags (1)
1 Solution

inventsekar
SplunkTrust
SplunkTrust

Hi Priya, with the "Splunk App for Unix and Linux", this will be an easy task.. without this App, you have to everything manually. 

ok, first lets try to monitor the folder /var/log/secure (the splunk user should have access to read this folder) and then once the logs reach Splunk, then you can check all details like login successful as well as failures and then you can drill down to the real issue of root user login failures(sudo failures).

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !

View solution in original post

0 Karma

inventsekar
SplunkTrust
SplunkTrust

@KSPriya ... Please suggest us...

1. do you use Splunk_TA_nix or not

2. do you want to monitor for the root user or any user?.. because, linux users generally login with their user access and then do the sudo to become root., right.. so you might want to monitor user login failures, right.. or sudo commands you want to monitor.. 

 

best regards,

Sekar

 

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

KSPriya
Explorer

Hello sekar,

Good day!!!

Thanks for your reply. Below are my comments:

1. do you use Splunk_TA_nix or not - we are not using Splunk_TA_nix

2. do you want to monitor for the root user or any user?.. because, linux users generally login with their user access and then do the sudo to become root., right.. so you might want to monitor user login failures, right.. or sudo commands you want to monitor.. - ---That's correct we can't directly access sudo user, but i'm looking is for sudo/root password reset attempts after multiple user login failures.

 

Regards,

Kspriya

 

inventsekar
SplunkTrust
SplunkTrust

Hi Priya, with the "Splunk App for Unix and Linux", this will be an easy task.. without this App, you have to everything manually. 

ok, first lets try to monitor the folder /var/log/secure (the splunk user should have access to read this folder) and then once the logs reach Splunk, then you can check all details like login successful as well as failures and then you can drill down to the real issue of root user login failures(sudo failures).

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma

KSPriya
Explorer

Thanks for the update champ

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...