Deployment Architecture

Are there related fields between sudo log and LDAP log? I want to monitor daily Linux sudo activity.

vicky05ssr04
Engager

I have a requirement for daily report of Linux sudo activity.

I came to know that the LDAP log will tell me if the user successfully has access, and sudo log will tell me what the execute request is and where?

Can I relate both logs using a common keyword or something to fetch results of both? I don't see one. Is there any approach tried by anyone on this, please let me know asap!

0 Karma

jfraiberg
Communicator

This really depends on how you are using ldap and sudo in your environment. Do the usernames match between the 2 log sources? If they do you should be able to easily correlate the 2. If they are not the same you could create a mapping between the 2 and use a lookup table or kvstore to facilitate the correlation.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...