Getting Data In

LINUX ESCU field values

herguzav
Explorer

Hello partners

I request your kind support as I intend to activate the Linux ESCU correlations, however these do not work well because the datamodels are not complete, I know they are necessary, but my observation is that the Linux events do not contain all the values ​​necessary to fill the datamodel. So my question to the community is the following: What audit, messages or syslog rules must be active for the correct collection of events?

Labels (3)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @herguzav ,

you should see your question in a different way:

what are your requisites?

what's the wanted result?

starting from this point of view, you can analyze your logs identifying the conditions to verify and if you already have the eventtypes and fields in the DataModel.

At least you can see if you really need to add a field or a constrain to the Datamodel.

Only for example (because it already exists): if you need to check the failed logins on Linux, you can analyze the Linux message ("Failed Password") and create (if not exists) the related eventtype, then you can see if you have in the Data Model the requested fields (e.g. user, source_ip, etc...), if not, you can add them.

Ciao.

Giuseppe

0 Karma

herguzav
Explorer

Hi

I understand your approach. However, ES ECU correlations are proposed by Splunk TEAM itself and these, in turn, are verified. So for these to work, the level of detail configurations or active rules so that the logs are created correctly in OS are the ones that I do not know and I ask your advice.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @herguzav ,

ESCu Correlation Search don't need additional fields, but you can customize your Correlation Searches adding fields to the Search and eventually to the Data Model.

But anyway, the correct approach is the one I described: you must start from the requisites and eventualli define customizations.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...