Splunk Enterprise Security

Linux Logs

sinhashubham014
Engager

I am working on Linux based usecases that are available in Splunk ESCU. Most of the usecases are using Endpoint. process data model. When checked in the official Splunk Linux add on, only 3 source types are shown in Endpoint i.e. (fs_notification, netstat, Unix:Service), Whereas the "process" sourcetype is not mapped with any data model. Will adding "process" sourcetype help in executing the Splunk ESCU queries?

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Don't modify the datamodel.  If you do then your local copy will override any future changes delivered by Splunk.

First, make sure the data in your "process" events apply to the Endpoint DM.  There may be too few common fields to make the DM useful.

If there is sufficient coverage in the DM for your data then use tags to ensure the DM finds the process events in its searches.  Define fieldaliases and EVALs as needed to make the data CIM-compliant.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Don't modify the datamodel.  If you do then your local copy will override any future changes delivered by Splunk.

First, make sure the data in your "process" events apply to the Endpoint DM.  There may be too few common fields to make the DM useful.

If there is sufficient coverage in the DM for your data then use tags to ensure the DM finds the process events in its searches.  Define fieldaliases and EVALs as needed to make the data CIM-compliant.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...

Share Your Feedback: On Admin Config Service (ACS)!

Help Us Build a Better Admin Config Service Experience (ACS)   We Want Your Feedback on Admin Config Service ...