Splunk Search

How to identify unauthorized access to crontab in a Splunk search?

TheJagoff
Communicator

Hello (again)

I am doing the following Linux command testing who has access to crontab.
For a non privileged user, I do the following under the user name "unauth":
mysearchhead> crontab -l
and receive the following:

You (unauth) are not allowed to use this program (crontab)
See crontab(1) for more information

In Splunk, I can see the attempt using:

host="mysearchhead" sourcetype=linux_audit a0=crontab  type=EXECVE

Resulting event is:

6/17/16 2:33:54.039 PM  
type=EXECVE msg=audit(1466174034.039:787184230): argc=2 a0="crontab" a1="-l"
host = mysearchhead     source = /var/log/audit/audit.log    sourcetype = linux_audit

My question is; where is the message stored that user "unauth" is not allowed to use this program?

Many thanks in advance

0 Karma
1 Solution

TheJagoff
Communicator

Found that I would need to ingest the cron log on any server that this condition is required.

View solution in original post

0 Karma

TheJagoff
Communicator

Found that I would need to ingest the cron log on any server that this condition is required.

0 Karma
Get Updates on the Splunk Community!

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...

September Community Champions: A Shoutout to Our Contributors!

As we close the books on another fantastic month, we want to take a moment to celebrate the people who are the ...

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...