Getting Data In

NFS file utilization auditing with Splunk on HP-UX servers

albertoperez
Explorer

Hi,
We are working to develop a Splunk project that audit the accesses and modifications to the files stored in several folders in several HP-UX servers, published by NFS.
Our first problems are blocking the project, so I hope you can help me with these:
1. The operating system logs show the actions executed in local over the files, with relative path, so we can´t identify certainly if a concrete file has been read / modified / deleted
2. One alternative is, having in mind each register in the log can identify the associated filesystem, mounting the folder to audit in an independent filesystem, but this idea generates the inconvenience of needing the constant mounting of this ‘extra’ filesystem in the monitored server. Anyway, this 'solution' only audit the local access, no via NFS.
3. By other hand, it exists a configuration parameter (‘audit_track_paths’) that enables the use of absolute paths, but this parameter only exists with HP-UV 11.31 version, and currently the customer servers haven´t got this version.
4. Finally, the audit files (not logs) in HP-UX systems are not plane text files, so we´d need any integration with Splunk taking advantage of the script data input. In the 'audit' command man page I found several C functions that enable to me to create a script to link it in a Script Data Input.

Have anybody any experience about any similar environment / project to help me or guide to me.

Thanks in advance.

Tags (4)

albertoperez
Explorer

Nice!
This is the way. 😉
Thank you Mario.

0 Karma

MarioM
Motivator

Here HP-UX Auditing some information and script about audit logs of the HP-UX servers.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...