Monitoring Splunk

Isilon FS Audit Logs Shows No User - Searching Index Shows SID

travismartinez
New Member

I'm having a challenge with the EMC Isilon Splunk App and Add-on that is reporting the SID information but not translating it to user/domain. There's not much in the way of directions for these and it seems like I missed a configuration step.

There are no errors being thrown and the index is taking in syslog information.

What do I need to do to get the FS Audit Logs to translate the user SID?

Thanks!

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...