Monitoring Splunk

FISMA Audit Index

seanp
Path Finder

I am trying to configure the FISMA application on a Splunk 4.3 installation using Windows. Specifically I am configuring the Audit Component on the Overview page as all three show No Results Found. When I view the FISMA_SG_audit_event index, it is shows an event count of 0. Does anyone know what audit logs this is coming from? Do I need to add something to the input.conf file or WMI.conf file? I am currently collecting the Application, Security, and System logs on the DCs via the Universal Forwarder.

Thanks

Tags (2)
0 Karma

piebob
Splunk Employee
Splunk Employee

if you're talking about the "Splunk for Fisma" app (http://splunk-base.splunk.com/apps/44883/splunk-for-fisma) the Splunkbase page for the app says
"This app does not provide data inputs, extractions, or tags itself." and goes on to explain that you need to configure inputs yourself via other technology add-ons and ensure the data conforms to the Splunk Common Information Model.

Get Updates on the Splunk Community!

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...