All Apps and Add-ons

TA_Linux_secure not parsing out "src" field for Failed password for invalid user

kmarciniak
Path Finder

PROBLEM: The field "src" is not parsed out for the "Failed password for invalid user" events but "src" is parsed out for the two PAM messages with rhost. If I do a failed login from a valid user account ie "Failed password for xxxxx" then "src" is parsed correctly but there are also no PAM messages with that event with any rhost fields so it seems to work correctly.

Below is a log sample for failed password for invalid user where the src is not parsed at all when PAM messages are also involved in the total login attempt.

Apr 9 14:43:48 test-backup sshd[16780]: PAM 2 more authentication failures; logname= uid=0 euid=0 tty=ssh ruser= rhost=192.168.224.24 << src is parsed
Apr 9 14:43:48 test-backup sshd[16780]: Failed password for invalid user april9 from 192.168.224.24 port 36392 ssh2 <

0 Karma
1 Solution

kmarciniak
Path Finder

Nevermind, i found a duplicate on this https://answers.splunk.com/answers/523160/confusing-behaviour-of-fieldalias.html. In my case its not 100% only the first log message get the src for a failed password log but now I know fieldalias run in parallel and no dependencies allow.

View solution in original post

0 Karma

kmarciniak
Path Finder

Nevermind, i found a duplicate on this https://answers.splunk.com/answers/523160/confusing-behaviour-of-fieldalias.html. In my case its not 100% only the first log message get the src for a failed password log but now I know fieldalias run in parallel and no dependencies allow.

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...