Splunk ITSI

does Splunk Enterprise or Splunk App for Infrastructure write any temporary files to /tmp/ folder (linux)?

qhmassc
Explorer

does Splunk Enterprise or Splunk App for Infrastructure write any temporary files to /tmp/ folder (linux)?

0 Karma

qhmassc
Explorer

McAfee complains cannot find tem files like:

ERROR OASManager [6611] skipping since file path /tmp/rERp5c could not be opened due to - No such file or directory.

I am not sure who created these tmp files like rERp5c, we have Splunk Enterprise and Splunk App for Infrastructure installed with this linux server.

is there any way we can capture who is writing temporary files to /tmp folder?

0 Karma

yannK
Splunk Employee
Splunk Employee

look at the file mod time, where they created around a splunk restart when the apps were installed?

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...