Splunk ITSI

does Splunk Enterprise or Splunk App for Infrastructure write any temporary files to /tmp/ folder (linux)?

qhmassc
Explorer

does Splunk Enterprise or Splunk App for Infrastructure write any temporary files to /tmp/ folder (linux)?

0 Karma

qhmassc
Explorer

McAfee complains cannot find tem files like:

ERROR OASManager [6611] skipping since file path /tmp/rERp5c could not be opened due to - No such file or directory.

I am not sure who created these tmp files like rERp5c, we have Splunk Enterprise and Splunk App for Infrastructure installed with this linux server.

is there any way we can capture who is writing temporary files to /tmp folder?

0 Karma

yannK
Splunk Employee
Splunk Employee

look at the file mod time, where they created around a splunk restart when the apps were installed?

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...