We are going to import RedHat web logs into Splunk for security monitoring. I was just wondering if anyone had any recommendations, based on your own experience, on apps I can use to make this process easier. So far, I've looked at Linux Auditd, Splunk App for Unix and Linux, and Red Hat Storage App for Splunk Enterprise (which I don't think fits my purposes). I just wanted to get other people's opinions on these apps, as well as hear any suggestions you have for alternatives.
If it matters, we are going to be using the logs for security, particularly in regards to detecting brute force attacks and privilege escalation.