Hi Splunk Community, We’re currently onboarding SUSE Linux (SLES/OpenSUSE) logs into Splunk Enterprise Security (ES) and would appreciate some input. Specifically, I’m looking to understand: What log files are most relevant for SUSE Linux when it comes to security-focused use cases in Splunk ES (e.g., authentication, audit, change tracking, endpoint monitoring)? How do SUSE Linux log paths and formats differ from standard Linux distributions like RHEL, CentOS, or Ubuntu? Are there any known configurations or tuning steps required (e.g., for /var/log/secure, auditd, or firewall logs) to ensure Splunk ES use cases are fully supported? If anyone has experience with Splunk ES and SUSE integration, I’d love to hear your recommendations on best practices or common challenges. Thanks in advance!
... View more