All Apps and Add-ons

Splunk Security Essentials v3.0.3 changes "source" for "monitor:///var/log/secure" in Splunk_TA_nix. Why?

rvany
Communicator

This is done in $SPLUNK_HOME/apps/Splunk_TA_nix/local/inputs.confand this is in "Splunk Add-on for Unix and Linux" in version 7.0.0 but I think that actually doesn't matter.

I found that the change comes from $SPLUNK_HOME/apps/Splunk_Security_Essentials/appserver/static/data_source.js (in line 1106 for v3.0.3). All other "source"-values for "monitor"-stanzas stay correct, i.e left unchanged at their default. This "secure"-source really should also stay at its original value, i.e. source=/var/log/secure.

Or is there a really good reason?

0 Karma
Get Updates on the Splunk Community!

Splunk at Cisco Live 2025: Learning, Innovation, and a Little Bit of Mr. Brightside

Pack your bags (and maybe your dancing shoes)—Cisco Live is heading to San Diego, June 8–12, 2025, and Splunk ...

Splunk App Dev Community Updates – What’s New and What’s Next

Welcome to your go-to roundup of everything happening in the Splunk App Dev Community! Whether you're building ...

The Latest Cisco Integrations With Splunk Platform!

Join us for an exciting tech talk where we’ll explore the latest integrations in Cisco + Splunk! We’ve ...