I have been trying to configure the Linux Auditd app to get it 100% functioning. Some of the panes are working and some are not. The app is not integrated with Splunk Enterprise Security (ES) and running on Splunk 6.5.1. Is this platform supported ? What would be the solution to fixing the errors below:
Please guide.
Have you completed the installation instructions for search environments with ES? https://github.com/doksu/splunk_auditd/wiki/Installation-and-Configuration#enterprise-security
Yea I have followed those instructions. I
Am testing this without ES.