Security

Does btool logs its usage somewhere?

jordanking1992
Path Finder

All,

Looking at some windows logs and came across the following commands ran on two separate computers. The "--no-log" concerns me and I can't seem to find if there is a place where logs would generate when this command is ran.

Has anyone seen or know why I would be seeing this? I am the only admin for these hosts so at first glance this looks like a bad actor.alt text

0 Karma

clozach
Path Finder

Hi did you ever determine what the root of this was? I'm seeing the same thing in my environment and would like to understand what's going on.

0 Karma

thambisetty
SplunkTrust
SplunkTrust

Can you try running btool with —no-log option and check if that’s displaying some output?

 

————————————
If this helps, give a like below.
0 Karma

splunker12er
Motivator

Can you post the full windows logs ? so to figure out why do you see these ?

0 Karma

PowerPacked
Builder

Hi @jordanking1992

Please check the usage of the btool command.

splunkhome/bin/splunk btool "conf file prefix" list --debug --app="appname"| grep "if you want to grep something from conf file"

and also use "> /var/tmp/123.txt" to write results into text file

here is the link to splunk doc

& splunk does writes logs about btool in splunkhome/var/log/splunk/bttol.log

Thanks

0 Karma

jordanking1992
Path Finder

Thanks for the information but the question is "What am I seeing in those screenshots?". I cannot find the --no-log anywhere in the documentation.

-Jordan

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out >> As our brave ...