Monitoring Splunk

FISMA Audit Index

seanp
Path Finder

I am trying to configure the FISMA application on a Splunk 4.3 installation using Windows. Specifically I am configuring the Audit Component on the Overview page as all three show No Results Found. When I view the FISMA_SG_audit_event index, it is shows an event count of 0. Does anyone know what audit logs this is coming from? Do I need to add something to the input.conf file or WMI.conf file? I am currently collecting the Application, Security, and System logs on the DCs via the Universal Forwarder.

Thanks

Tags (2)
0 Karma

piebob
Splunk Employee
Splunk Employee

if you're talking about the "Splunk for Fisma" app (http://splunk-base.splunk.com/apps/44883/splunk-for-fisma) the Splunkbase page for the app says
"This app does not provide data inputs, extractions, or tags itself." and goes on to explain that you need to configure inputs yourself via other technology add-ons and ensure the data conforms to the Splunk Common Information Model.

Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...