Security

check the permissions on the log files which are configured on Splunk

Allampally
Path Finder

Hi,

Is there any way to find the file permissions for any file which is configured in Splunk.
Let's say, a file has the 750 permission with root user etc.

Tags (1)
0 Karma

bandit
Motivator

This should work. I haven't yet updated it to state Splunk 7.x compatible, however it should really work on any version of Splunk. Please note you have to set the execute bit on the .sh file after installing to deployment-apps on your deployment server.

Check Log Permissions Technology Add-on https://splunkbase.splunk.com/app/3014/

0 Karma

koshyk
Super Champion

I assume; mean when you "configured on Splunk" means files to be read by Splunk agent? If yes, the best way is to create a group (eg logger) and ensure splunk is member of the group logger and the file to have permission of logger . Something of below format

rwxr----- root logger   /var/log/syslog/somefile.log

This way, the file can be owned by any other user, but splunk should be able to read the file

In Linux, you could do a bulk level check of file permissions. So the below will find ALL files, with pattern of *.log in /var/log and do list of files with permissions

find /var/log -type f -name '*.log' -exec ls -l {} \; 

..

0 Karma

DavidHourani
Super Champion

Hi @Allampally,

The best way to go about this is to build a scripted input to read ls -lhon your files.

You would then be able to keep a history of changes of permissions on any files/directory you choose to monitor. Let me know if you need an example of how to build one.

Cheers,
David

0 Karma

Allampally
Path Finder

Could you please provide an example

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...