Getting Data In

Does Splunk Universal Forwarder forward audit events

Contributor

Does Splunk Universal Forwarder forward audit event logs to Splunk _audit index?
I can see Splunk HF's are forwarding audit events, but couldn't find which app has inputs.conf which enable reading audit logs and forward to _audit index.

May I know which app consists inputs to read and send data to _audit index in Splunk?

0 Karma

SplunkTrust
SplunkTrust

You would see default/outputs.conf on the SplunkForwarder app with

[tcpout]
forwardedindex.x.whitelist= (_audit | _introspection | _telemetry)

This would forward all the _* logs to index layer.

0 Karma

SplunkTrust
SplunkTrust

Hi ankithreddy777
they are in system/default and/or system/local.
Bye.
Giuseppe

SplunkTrust
SplunkTrust

Hi ankithreddy777
if you're satisfied by this answer, please accept and/or upvote it.

Bye, see next time.
Giuseppe

0 Karma
Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes
and swag!