Deployment Architecture

How to get logs for file deletion from Linux environment

kbhardwaj
Engager

I have been searching for logs specific to file deletion from Linux servers. I've searched audit logs but do not get any relevant logs . I have also searched in auth folder. Can anyone help me identify which folder to look in for logs that are being ingested into Splunk?

Tags (2)
0 Karma

afamoyib
Path Finder

If you can't use something like inotify to update you. The next best thing i can think of is to monitor the history command for any time the rm command is called. That is the next best thing i can think of. This way you can setup a search for anytime the remove command is used and this can be a report or an alert based on the condition you would like

0 Karma

jplumsdaine22
Influencer

It is unlikely this is being logged by default on a standard *nix system. Your sysadmins should be able to set something up for you (have a google, it depends on your distribution) and then its just a matter of adding those logs to Splunk.

If the files are on some kind of filer that may be a different matter, again it will depend on the vendor.

0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...