Splunk Enterprise

How can I generate apparmor profile for my Splunk forwarder agent?

subramanianers
Loves-to-Learn Lots

I am trying to construct an apparmor profile for my Splunk forwarder agent. I have installed the agent and it is currently sending logs to my Splunk Enterprise server. But when I try to generate apparmor profiles using "aa-genprof" command, I do not see any actions in the output.

 

How can I generate apparmor profile for my Splunk forwarder agent? I could not find any predefined profiles on the internet either.

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Per this site (https://www.linuxtopia.org/online_books/opensuse_guides/apparmor_guide/apparmor_bx5bml8.html), aa-genprof is not suitable for long-running processes like the Splunk Universal Forwarder.  Instead, follow the site's steps for systemic profiling.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

How to Get Started with Splunk Data Management Pipeline Builders (Edge Processor & ...

If you want to gain full control over your growing data volumes, check out Splunk’s Data Management pipeline ...

Out of the Box to Up And Running - Streamlined Observability for Your Cloud ...

  Tech Talk Streamlined Observability for Your Cloud Environment Register    Out of the Box to Up And Running ...

Splunk Smartness with Brandon Sternfield | Episode 3

Hello and welcome to another episode of "Splunk Smartness," the interview series where we explore the power of ...