Getting Data In

LINUX ESCU field values

herguzav
Explorer

Hello partners

I request your kind support as I intend to activate the Linux ESCU correlations, however these do not work well because the datamodels are not complete, I know they are necessary, but my observation is that the Linux events do not contain all the values ​​necessary to fill the datamodel. So my question to the community is the following: What audit, messages or syslog rules must be active for the correct collection of events?

Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @herguzav ,

you should see your question in a different way:

what are your requisites?

what's the wanted result?

starting from this point of view, you can analyze your logs identifying the conditions to verify and if you already have the eventtypes and fields in the DataModel.

At least you can see if you really need to add a field or a constrain to the Datamodel.

Only for example (because it already exists): if you need to check the failed logins on Linux, you can analyze the Linux message ("Failed Password") and create (if not exists) the related eventtype, then you can see if you have in the Data Model the requested fields (e.g. user, source_ip, etc...), if not, you can add them.

Ciao.

Giuseppe

0 Karma

herguzav
Explorer

Hi

I understand your approach. However, ES ECU correlations are proposed by Splunk TEAM itself and these, in turn, are verified. So for these to work, the level of detail configurations or active rules so that the logs are created correctly in OS are the ones that I do not know and I ask your advice.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @herguzav ,

ESCu Correlation Search don't need additional fields, but you can customize your Correlation Searches adding fields to the Search and eventually to the Data Model.

But anyway, the correct approach is the one I described: you must start from the requisites and eventualli define customizations.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

ATTENTION!! We’re MOVING (not really)

Hey, all! In an effort to keep this Slack workspace secure and also to make our new members' experience easy, ...

Splunk Admins: Build a Smarter Stack with These Must-See .conf25 Sessions

  Whether you're running a complex Splunk deployment or just getting your bearings as a new admin, .conf25 ...

AppDynamics Summer Webinars

This summer, our mighty AppDynamics team is cooking up some delicious content on YouTube Live to satiate your ...