All Apps and Add-ons

Linux AuditD - Missing inputs.conf?

nhertzberg
New Member

I was installing the Linux AuditD app and the TA on my Splunk instance and my forwarders installed on RHEL 7 systems when I noticed that there's no inputs.conf file in either the app or the TA. How are my indexers supposed to get and use any data from the systems without the forwarders sending the data over? Am I just supposed to make one myself?

I had a look at the video guide for version v2 (something like 6 years ago), and that one seems to have an inputs.conf file, unlike the current version v3.

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

with quick look, this TA/app didn't contains any inputs at all. This is just for presenting auditd events on SH and also do needed filed extractions on SH/Indexer/HF. See https://github.com/doksu/splunk_auditd/wiki/Installation-and-Configuration

To get events from clients you should use e.g. your own TA with inputs or use e.g. Splunk Add-on for Unix and Linux https://splunkbase.splunk.com/app/833 to collect those from UFs

r. Ismo

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...