Splunk ITSI

does Splunk Enterprise or Splunk App for Infrastructure write any temporary files to /tmp/ folder (linux)?

qhmassc
Explorer

does Splunk Enterprise or Splunk App for Infrastructure write any temporary files to /tmp/ folder (linux)?

0 Karma

qhmassc
Explorer

McAfee complains cannot find tem files like:

ERROR OASManager [6611] skipping since file path /tmp/rERp5c could not be opened due to - No such file or directory.

I am not sure who created these tmp files like rERp5c, we have Splunk Enterprise and Splunk App for Infrastructure installed with this linux server.

is there any way we can capture who is writing temporary files to /tmp folder?

0 Karma

yannK
Splunk Employee
Splunk Employee

look at the file mod time, where they created around a splunk restart when the apps were installed?

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...