Hi!
i have configred ubuntu machine to send authentication log to my splunk instance using syslog.
But i found just the failed auth logs and other logs with the field " pam_unix(cron:session)".
i am looking for the successful authentication that have the field "pam_unix(login:session)" and i find just pam_unix(sudo:session)
Do i need to use add-on for unix and linux ?
Any advice, tips, or resources you can provide will be highly appreciated
Thank you