Monitoring Splunk

Inserting mac os event logs in splunk

pulen
New Member

I am really struggling to add my macos data into splunk just like how we can upload the event logs of windows. is there any add-ons that i can install to help me do this? if there is, can anyone explain how to configure it and make it work? 

Labels (1)
0 Karma

deepakc
Contributor

To get you started here's a number of links for you read and work through

In short you need the nix TA, UF and configure inputs and outputs based on your requirements.

#This shows you the TA Required (Nix TA)
https://splunkbase.splunk.com/app/833


#This shows you the OS Supported = MacOs is listed
https://docs.splunk.com/Documentation/AddOns/latest/UnixLinux/About

 

#Read the release notes
https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Releasenotes

And you will need to install a Universal Forwarder for the MacOS + configure outputs and TA inputs
https://www.splunk.com/en_us/download/universal-forwarder.html

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...