Security

check the permissions on the log files which are configured on Splunk

Allampally
Path Finder

Hi,

Is there any way to find the file permissions for any file which is configured in Splunk.
Let's say, a file has the 750 permission with root user etc.

Tags (1)
0 Karma

bandit
Motivator

This should work. I haven't yet updated it to state Splunk 7.x compatible, however it should really work on any version of Splunk. Please note you have to set the execute bit on the .sh file after installing to deployment-apps on your deployment server.

Check Log Permissions Technology Add-on https://splunkbase.splunk.com/app/3014/

0 Karma

koshyk
Super Champion

I assume; mean when you "configured on Splunk" means files to be read by Splunk agent? If yes, the best way is to create a group (eg logger) and ensure splunk is member of the group logger and the file to have permission of logger . Something of below format

rwxr----- root logger   /var/log/syslog/somefile.log

This way, the file can be owned by any other user, but splunk should be able to read the file

In Linux, you could do a bulk level check of file permissions. So the below will find ALL files, with pattern of *.log in /var/log and do list of files with permissions

find /var/log -type f -name '*.log' -exec ls -l {} \; 

..

0 Karma

DavidHourani
Super Champion

Hi @Allampally,

The best way to go about this is to build a scripted input to read ls -lhon your files.

You would then be able to keep a history of changes of permissions on any files/directory you choose to monitor. Let me know if you need an example of how to build one.

Cheers,
David

0 Karma

Allampally
Path Finder

Could you please provide an example

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...