Monitoring Splunk

Splunk generating tons of fcntl Solaris audit records

dcarlo
New Member

I have a Solaris 10 SPARC server that is running Splunk 4.1. It's configured to generate audit logs to syslog, create local log files, and Splunk is configured to forward them to a central Splunk server. The problem that I'm having is that Splunk is generating thousands of audit records per minute. They are all fcntl system calls. Here's an example record from praudit:

header,168,2,fcntl(2),,unixhost,2010-07-07 08:01:46.018 -04:00,argument,2,0x3,cmd,argument,1,0x16,no path: fd,attribute,140666,root,root,331,48471,0,subject,localuser,splunk,splunk,splunk,splunk,1343,1687751497,15720 196630 192.168.99.5,return,success,2,zone,global,sequence,4773104,trailer,168

Has anybody seen this?

--Dave

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

I suppose one question is what your BSM system is set up to audit. It's entirely normal for Splunk to be reading and writing many files a lot (that is it's purpose) and thousands of reads and writes per minute doesn't seem unreasonable, but it depends on whether these are files it is supposed to be reading and writing.

Get Updates on the Splunk Community!

Preparing your Splunk Environment for OpenSSL3

The Splunk platform will transition to OpenSSL version 3 in a future release. Actions are required to prepare ...

Deprecation of Splunk Observability Kubernetes “Classic Navigator” UI starting ...

Access to Splunk Observability Kubernetes “Classic Navigator” UI will no longer be available starting January ...

Now Available: Cisco Talos Threat Intelligence Integrations for Splunk Security Cloud ...

At .conf24, we shared that we were in the process of integrating Cisco Talos threat intelligence into Splunk ...