Splunk Search

Linux mounting/unmounting

mvitullo
New Member

I am attempting to create a search string for a Linux box which involves mounting/unmounting removable media devices (ie., CDs and USB devices) Any help would be welcome.

Tags (2)
0 Karma

marycordova
SplunkTrust
SplunkTrust

What you need to do is perform some stimulus response testing and development.

  1. ask the admin what linux distro and version they are running
  2. setup a vm for the distro and install a universal forwarder on it
  3. forward the logs to splunk enterprise (can be local install to your laptop/workstation where the vm is or wherever you have a splunk enterprise instance available for this dev work)
  4. perform the actions you want to write and alert for - plug in usbs, mount cds, etc
  5. look at the raw logs and write your alerts, during your analysis you might be able to generalize the alert such that it can be applied to more than one linux distro (would still require testing and validation)
  6. perhaps install the *nix app/ta to get some quick win parsing before starting the log analysis

You might also try the splunk security essentials app on splunk base, it might have some of this built already and you could just copy the searches, you would still likely benefit from testing it against a vm with proper disto.

@marycordova
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's not clear what you seek. Please explain your use case.

---
If this reply helps you, Karma would be appreciated.
0 Karma

mvitullo
New Member

I have a system admininistrator who requires a dashboard for their Linux OS. This dashboard is to be used for providing when any users place (mount) and/or remove (unmount) any form of removable media from the machine. The search string would look for any events where this would occur.

0 Karma

mlinde
Explorer

Couple questions up front:
1. Do you already collect logs on these linux systems?
2. Are you forwarding these logs into splunk already?
3. What variations of Linux are you looking to report against?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Persistent Queue at TcpOut — One of Splunk's Most Practical Features

Splunk introduced persistent queueing at the tcpout layer as one of the most practical resilience features in ...

Skip the Awkward Silence: Have a .conf-ersation at .conf26

Picture this. You arrive at .conf26 already having your socializing and networking plans mapped out. No ...

Rethinking Zero Trust: From Product Purchases to Logical Control Evidence

Implementing Zero Trust (ZT) across complex environments often falters at the very beginning due to a ...