does Splunk Enterprise or Splunk App for Infrastructure write any temporary files to /tmp/ folder (linux)?
McAfee complains cannot find tem files like:
ERROR OASManager [6611] skipping since file path /tmp/rERp5c could not be opened due to - No such file or directory.
I am not sure who created these tmp files like rERp5c, we have Splunk Enterprise and Splunk App for Infrastructure installed with this linux server.
is there any way we can capture who is writing temporary files to /tmp folder?
look at the file mod time, where they created around a splunk restart when the apps were installed?