I want to know if it is possible to do a script which read a file and correlate the data in this file with an event in Splunk.
For example, when I put a USB key in Linux, I have this log:
Jan 31 11:02:51 PFSplunkCentOS5 hald: mounted /dev/sdb1 on behalf of uid 0
and I want to correlate UID 0 with the
file /etc/passwd and say
uid 0 = root or other user and put root in the event in Splunk like metadata.
How can read the /etc/passwd file to correlate the uid with the user because the "lookup" function uses only KML, KMZ and CSV and I want to use the "/etc/passwd" which isn't a KML, KMZ or CSV file.