All Apps and Add-ons

How to forward nix auditd data from UF to Indexer

token2
Path Finder

I have installed auditd app and TA on my indexer/search head but this is a free license, I do not have deployment capability. How do I configure a linux machine's UF to forward the necessary logs to the indexer? I already have the UF 9997 output pointing to my indexer and my indexer set to receive, but do I need to manually copy over the auditd TA-Linux_auditd app contents to the UF's apps path?

0 Karma
Get Updates on the Splunk Community!

Unlock New Opportunities with Splunk Education: Explore Our Latest Courses!

At Splunk Education, we’re dedicated to providing top-tier learning experiences that cater to every skill ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...