Linux Secure Technology Add-On

Splunk Community

Linux Secure Technology Add-On

Linux Secure Technology Add-On
This app provides field extractions and normalisation to the Common Information Model for /var/log/secure and /var/log/auth.log (linux_secure sourcetype). It is intended to replace the security-relevant aspects of the Splunk Add-on for Unix and Linux (Splunk_TA_nix) and as such it's strongly recommended that the Splunk_TA_nix app be removed from your search head before installing this app as they may conflict. This app requires no configuration and need only be installed on search heads (i.e. contains no index-time transforms). Be sure to also check out the certified sudo (https://splunkbase.splunk.com/app/3038/), iptables (https://splunkbase.splunk.com/app/3089/) and auditd (https://splunkbase.splunk.com/app/2642/) apps. For Linux performance monitoring, please see: https://splunkbase.splunk.com/app/3412/
0 topics and 0 replies mentioned Linux Secure Technology Add-On in
Latest Topics
No posts to display.
Latest Replies
No posts to display.
Top Topics
No posts to display.
My Topics
No posts to display.