Getting Data In

LINUX ESCU field values

herguzav
Explorer

Hello partners

I request your kind support as I intend to activate the Linux ESCU correlations, however these do not work well because the datamodels are not complete, I know they are necessary, but my observation is that the Linux events do not contain all the values ​​necessary to fill the datamodel. So my question to the community is the following: What audit, messages or syslog rules must be active for the correct collection of events?

Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @herguzav ,

you should see your question in a different way:

what are your requisites?

what's the wanted result?

starting from this point of view, you can analyze your logs identifying the conditions to verify and if you already have the eventtypes and fields in the DataModel.

At least you can see if you really need to add a field or a constrain to the Datamodel.

Only for example (because it already exists): if you need to check the failed logins on Linux, you can analyze the Linux message ("Failed Password") and create (if not exists) the related eventtype, then you can see if you have in the Data Model the requested fields (e.g. user, source_ip, etc...), if not, you can add them.

Ciao.

Giuseppe

0 Karma

herguzav
Explorer

Hi

I understand your approach. However, ES ECU correlations are proposed by Splunk TEAM itself and these, in turn, are verified. So for these to work, the level of detail configurations or active rules so that the logs are created correctly in OS are the ones that I do not know and I ask your advice.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @herguzav ,

ESCu Correlation Search don't need additional fields, but you can customize your Correlation Searches adding fields to the Search and eventually to the Data Model.

But anyway, the correct approach is the one I described: you must start from the requisites and eventualli define customizations.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...