Splunk Search

Can an ausearch command be used in the search field?

amortiz
Explorer

I am attempting to convert a audit script on my linux audit server into something manageable in Splunk.
Can I use the commands from the script in Splunk?

An ausearch example is below.
- ausearch –k logins and ausearch –m USER_LOGIN

Tags (4)
0 Karma

lukejadamec
Super Champion

No, ausearch is a unix command. What you can do is write a script that uses ausearch to monitor the audit logs, and have that output indexed. The TA_for_Nix app does that with rlog.sh script.

Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...