Splunk IT Service Intelligence

does Splunk Enterprise or Splunk App for Infrastructure write any temporary files to /tmp/ folder (linux)?

qhmassc
Explorer

does Splunk Enterprise or Splunk App for Infrastructure write any temporary files to /tmp/ folder (linux)?

0 Karma

qhmassc
Explorer

McAfee complains cannot find tem files like:

ERROR OASManager [6611] skipping since file path /tmp/rERp5c could not be opened due to - No such file or directory.

I am not sure who created these tmp files like rERp5c, we have Splunk Enterprise and Splunk App for Infrastructure installed with this linux server.

is there any way we can capture who is writing temporary files to /tmp folder?

0 Karma

yannK
Splunk Employee
Splunk Employee

look at the file mod time, where they created around a splunk restart when the apps were installed?

0 Karma
Get Updates on the Splunk Community!

This Week's Community Digest - Splunk Community Happenings [9.26.22]

Get the latest news and updates from the Splunk Community here! Upcoming User Group Events! 👏 Check ...

BSides Splunk 2022 - The Call for Papers is now Open!

TLDR; Main Site: https://bsidessplunk.com CFP Site: https://bsidessplunk.com/cfp CFP Opens: December 15th, ...

Sending Metrics to Splunk Enterprise With the OpenTelemetry Collector

This blog post is part of an ongoing series on OpenTelemetry. The OpenTelemetry project is the second largest ...