Splunk Enterprise Security

Can you help me understand why my /var/log/secure useradd field extractions are not working as expected?

daniel333
Builder

All,

I have a clean install of Splunk ES with the latest Splunk App For Nix enabled. The Account Management dashboard is not populating in a useful.

I have this log event which is my test -
Apr 10 19:44:10 myhost useradd[5965]: new user: name=mysql, UID=997, GID=994, home=/var/lib/mysql, shell=/bin/bash

SHOULD pull field extraction from this out of the box transform stanza -

[useradd]
REGEX = .*?((new) (user|group|account))(?:: | (?:added) - )(?:name|account)=(\w+),
FORMAT = vendor_action::$1 object_category::$3 name::$4 user::$4

I confirmed you stanza SHOULD work in regex101.com

Can you help me understand why this isn't working as I expect? I believe users added, removed, groups added, removed should appear here by who executed the command.

0 Karma

p_gurav
Champion

Can you also verify the sourcetype name in both application and in normal search? Also try running dashboard search manually and check which parameter is not match.

0 Karma

FrankVl
Ultra Champion

Also: the account management dashboard probably relies on the Change Analysis data model. So you may want to check if that is being populated correctly.

0 Karma

daniel333
Builder

Ended up finding the default lookup tables were missing entries for my OS. Aftermanually adding them I was set. Send in the missing elements to support to maybe they'll make their way into the next release.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...