Getting Data In

How to onboard AIX wtmp logs to splunk?

pshelke
Observer

We would like to know how to onboard an AIX wtmp logs to splunk ?Can it be done via Universal Forwarder ? If so can you please help us with the documentations for onboarding AIX logs ?

 

 

Labels (1)
0 Karma

isoutamo
SplunkTrust
SplunkTrust

Hi

It's long time when I have last manage AIX so this comes from my memory as I cannot check it in any AIX boxes.

you can use UF on AIX as any other *nix OS. There are some different way how you should configure it to run at boot, but there are instructions on installation guide (at least on enterprise, cannot recall if it is also on UF guide or not?).

If I recall right wtmp log is binary? If so you must use some script to convert it to text first (or was this converted to some another log daily base?). Another way is use some splunk command to read it and then use that output for UF's input.

You probably need to add some read access to splunk user as those files/commands are not available for normal users.

r. Ismo

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Think Like an Architect: Introducing the Splunk Certified Cybersecurity Defense ...

In cybersecurity, defenders respond to threats. Architects design the systems that stop them.    As ...

Index This | What has goals but no motivation?

June 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Deep Dive: Accelerate threat investigation with Splunk’s AI Assistant in Security

AI is one of the biggest topics in the market today, and for security teams, its value goes far beyond the ...