Getting Data In

.bash_history

raiqbal47010
New Member

I have multisite environment and I want to monitor all the ssh user commands through .bash_history.
for that purpose I enable the monitor:// stanza in all splunk components. interestingly, I am seeing bash_history logs from some servers and majority of the servers are not showing me logs whereas the same configuraiton is across the border.
please advise.

0 Karma
1 Solution

PavelP
Motivator

Hello @raiqbal47010

have you followed best practices for bash_history ingestion?

Based on this great post https://www.duanewaddle.com/splunking-bash-history/ by @dwaddle

https://github.com/duckfez/splunk-TA-bash_history

https://visibleninja.guru/splunking-bash-history/

View solution in original post

PavelP
Motivator

Hello @raiqbal47010

have you followed best practices for bash_history ingestion?

Based on this great post https://www.duanewaddle.com/splunking-bash-history/ by @dwaddle

https://github.com/duckfez/splunk-TA-bash_history

https://visibleninja.guru/splunking-bash-history/

raiqbal47010
New Member

I am getting below error on splunk instances:
not exporting configurations globally to system.
and seondly no commonds shown up when I press up arrown OR down arrow. even no history when i give history command. ?

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...