Getting Data In

Splunk add-on for Fudo PAM | How to parse logs from Fudo?

splunky_diamond
Path Finder

Hello splunkers!

Has anyone had experience with getting data in Splunk from PAM (Privileged Access Management) systems? I want to do the integration of Splunk with Fudo PAM. Question of getting logs from Fudo to Splunk is not a problem at all, it's easily done over syslog. However, I don't know how to parse these logs. The syslog sourcetype doesn't properly parse the events, it misses a lot of useful information such as: users, processes, action done, accounts, basically almost everything except for the IP of the node and the timestamp of the event. 

Does anyone know if there is a good add-on for parsing logs from Fudo PAM? Or any other good way how to parse its logs? 

Thanks for taking time reading and replying to my post ❤️

Labels (2)
0 Karma

tej57
Contributor

Hello @splunky_diamond ,

I am unsure if there are any apps/TAs available for Fudo PAM data. The best would be to write magic 8 props for parsing the data. You can find the relevant documentation links below:

https://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkdoeswithyourdata

https://docs.splunk.com/Documentation/Splunk/latest/Data/Overviewofeventprocessing

https://docs.splunk.com/Documentation/Splunk/latest/Data/Createsourcetypes

https://lantern.splunk.com/Splunk_Platform/Product_Tips/Data_Management/Configuring_new_source_types

 

Thanks,
Tejas.

 

---

If the above solution helps, an upvote is appreciated.

Get Updates on the Splunk Community!

Prove Your Splunk Prowess at .conf25—No Prereqs Required!

Your Next Big Security Credential: No Prerequisites Needed We know you’ve got the skills, and now, earning the ...

Splunk Observability Cloud's AI Assistant in Action Series: Observability as Code

This is the sixth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Answers Content Calendar, July Edition I

Hello Community! Welcome to another month of Community Content Calendar series! For the month of July, we will ...