All Apps and Add-ons

Linux auditd app user tty configuration.

jcorkey
Explorer

How do I configure the user tty Dashboard in Linux auditd app? I have the Linux audit app running on my indexer and I know I have to configure my forwarder in order for the keystroke logging to work but the documentation for the Linux auditd app that shows how to configure this is not helping. I followed the documentation instructions for adding the changes to the password-auth and system-auth files under the pam.d directory and I can't get it to work. Is there any more changes I need to make? Nothing in the user tty dashboard will populate. Is there any other info or documentation that could possibly help?

0 Karma

klaxdal
Contributor

Assume you have run the " Configure Dashboard " ? Try running it for " All time " this will populate your learnt_posix_identities KVStore collection .

From there - to test TTY , explicitly enter a POSIX user ( rather than use the wild card ) in the appropriate field on the User TTY dashboard .

Works well in my environment

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...