Security

check the permissions on the log files which are configured on Splunk

Allampally
Path Finder

Hi,

Is there any way to find the file permissions for any file which is configured in Splunk.
Let's say, a file has the 750 permission with root user etc.

Tags (1)
0 Karma

bandit
Motivator

This should work. I haven't yet updated it to state Splunk 7.x compatible, however it should really work on any version of Splunk. Please note you have to set the execute bit on the .sh file after installing to deployment-apps on your deployment server.

Check Log Permissions Technology Add-on https://splunkbase.splunk.com/app/3014/

0 Karma

koshyk
Super Champion

I assume; mean when you "configured on Splunk" means files to be read by Splunk agent? If yes, the best way is to create a group (eg logger) and ensure splunk is member of the group logger and the file to have permission of logger . Something of below format

rwxr----- root logger   /var/log/syslog/somefile.log

This way, the file can be owned by any other user, but splunk should be able to read the file

In Linux, you could do a bulk level check of file permissions. So the below will find ALL files, with pattern of *.log in /var/log and do list of files with permissions

find /var/log -type f -name '*.log' -exec ls -l {} \; 

..

0 Karma

DavidHourani
Super Champion

Hi @Allampally,

The best way to go about this is to build a scripted input to read ls -lhon your files.

You would then be able to keep a history of changes of permissions on any files/directory you choose to monitor. Let me know if you need an example of how to build one.

Cheers,
David

0 Karma

Allampally
Path Finder

Could you please provide an example

0 Karma
Get Updates on the Splunk Community!

What's New in Splunk Enterprise 9.4: Features to Power Your Digital Resilience

Hey Splunky People! We are excited to share the latest updates in Splunk Enterprise 9.4. In this release we ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...