Splunk Enterprise Security

Does anyone have a walk through or tutorial on setting up the time_center in Splunk ES on Linux hosts?



Does anyone have a walk through on setting up the time center on Splunk ES for Linux (centOS 7 in this case) hosts? I have the time.sh input from SPlunk_TA_nix going but doesn't work out of the box. Other NTP app on splunkbase don't even have tags/eventtypes that I looked at. Any direction on here would be great.

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!