All Apps and Add-ons

Splunk Security Essentials v3.0.3 changes "source" for "monitor:///var/log/secure" in Splunk_TA_nix. Why?

rvany
Communicator

This is done in $SPLUNK_HOME/apps/Splunk_TA_nix/local/inputs.confand this is in "Splunk Add-on for Unix and Linux" in version 7.0.0 but I think that actually doesn't matter.

I found that the change comes from $SPLUNK_HOME/apps/Splunk_Security_Essentials/appserver/static/data_source.js (in line 1106 for v3.0.3). All other "source"-values for "monitor"-stanzas stay correct, i.e left unchanged at their default. This "secure"-source really should also stay at its original value, i.e. source=/var/log/secure.

Or is there a really good reason?

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...