Dashboards & Visualizations

AU-2 Audit events

JIreland
New Member

Hello,

Newb here trying to get up to speed...

I need to create dashboards that will allow me to perform the audit events listed in the JSIG:

1. Authentication events:
    (1) Logons (Success/Failure)
    (2) Logoffs (Success)
2. Security Relevant File and Objects events:
    (1) Create (Success/Failure)
    (2) Access (Success/Failure)
    (3) Delete (Success/Failure)
    (4) Modify (Success/Failure)
    (5) Permission Modification (Success/Failure)
    (6) Ownership Modification (Success/Failure)
3. Export/Writes/downloads to devices/digital media (e.g., CD/DVD, USB, SD) (Success/Failure)
4. Import/Uploads from devices/digital media (e.g., CD/DVD, USB, SD) (Success/Failure)
5. User and Group Management events:
    (1) User add, delete, modify, disable, lock (Success/Failure)
    (2) Group/Role add, delete, modify (Success/Failure)
6. Use of Privileged/Special Rights events:
    (1) Security or audit policy changes (Success/Failure)
    (2) Configuration changes (Success/Failure)
7. Admin or root-level access (Success/Failure)
8. Privilege/Role escalation (Success/Failure)
9. Audit and security relevant log data accesses (Success/Failure)
10. System reboot, restart and shutdown (Success/Failure)
11. Print to a device (Success/Failure)
12. Print to a file (e.g., pdf format) (Success/Failure)
13. Application (e.g., Adobe, Firefox, MS Office Suite) initialization

 

Are there templated Splunk search commands for these? And if so, could you point me to them? Many thanks!

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

You probably have getting that data in with Splunk's Windos and *nix Add-ones? If not then I strongly recommend you to use those! With those you will get events as CIM compliant. That way it's much easier to look some other apps from splunk base which are using CIM to create those queries for you dashboard(s).

Here is some apps from splunkbase:

Those are just order which I get from my SCP instance, not any preferred etc.

r. Ismo

0 Karma

livehybrid
SplunkTrust
SplunkTrust

Hi @JIreland 

This will entirely depend on the sourcetypes that you are feeding in to Splunk. What is the source of your Audit data?

There may be some pre-build dashboards for some of these in apps specific to the type of data you are bringing in. Otherwise it might be a case of working through the data to put together each of these.

When you are putting together the dashboards, bear in mind that sometimes things within dashboards can be missed or overlooked if crowded, and that things like alerts may be more suitable for rare events that you need to know about.

Please let me know how you get on and consider accepting this answer or adding karma this answer if it has helped.
Regards

Will

 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...