Splunk Enterprise Security

Linux Auditd: How to get this app working with Splunk Enterprise Security?

naqviah
Explorer

I have been trying to configure the Linux Auditd app to get it 100% functioning. Some of the panes are working and some are not. The app is not integrated with Splunk Enterprise Security (ES) and running on Splunk 6.5.1. Is this platform supported ? What would be the solution to fixing the errors below:

  • Error in 'PivotProcessor': Error in 'DataModelEvaluator': Data model 'Auditd' was not found.
  • Error in 'lookup' command: The lookup table 'posix_identities' does not exist or is not available.
  • The lookup table 'auditd_host_inventory' does not exist. It is referenced by configuration 'linux:audit'.

Please guide.

0 Karma

doksu
Contributor

Have you completed the installation instructions for search environments with ES? https://github.com/doksu/splunk_auditd/wiki/Installation-and-Configuration#enterprise-security

naqviah
Explorer

Yea I have followed those instructions. I
Am testing this without ES.

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...