Getting Data In

How do you audit for who is disabling Data Input?

New Member

Recently, we found one data input for receiving syslog was stopped.

We don't know if the service issue is auto stop or someone disabling it. i tried to search index=_audit,

Also, I even saw some log edit server, only see the action is edit server but it didn't mention what setting had been changed.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!