Splunk Search

Linux mounting/unmounting

mvitullo
New Member

I am attempting to create a search string for a Linux box which involves mounting/unmounting removable media devices (ie., CDs and USB devices) Any help would be welcome.

Tags (2)
0 Karma

marycordova
SplunkTrust
SplunkTrust

What you need to do is perform some stimulus response testing and development.

  1. ask the admin what linux distro and version they are running
  2. setup a vm for the distro and install a universal forwarder on it
  3. forward the logs to splunk enterprise (can be local install to your laptop/workstation where the vm is or wherever you have a splunk enterprise instance available for this dev work)
  4. perform the actions you want to write and alert for - plug in usbs, mount cds, etc
  5. look at the raw logs and write your alerts, during your analysis you might be able to generalize the alert such that it can be applied to more than one linux distro (would still require testing and validation)
  6. perhaps install the *nix app/ta to get some quick win parsing before starting the log analysis

You might also try the splunk security essentials app on splunk base, it might have some of this built already and you could just copy the searches, you would still likely benefit from testing it against a vm with proper disto.

@marycordova
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's not clear what you seek. Please explain your use case.

---
If this reply helps you, Karma would be appreciated.
0 Karma

mvitullo
New Member

I have a system admininistrator who requires a dashboard for their Linux OS. This dashboard is to be used for providing when any users place (mount) and/or remove (unmount) any form of removable media from the machine. The search string would look for any events where this would occur.

0 Karma

mlinde
Explorer

Couple questions up front:
1. Do you already collect logs on these linux systems?
2. Are you forwarding these logs into splunk already?
3. What variations of Linux are you looking to report against?

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...