Splunk IT Service Intelligence

does Splunk Enterprise or Splunk App for Infrastructure write any temporary files to /tmp/ folder (linux)?

qhmassc
Explorer

does Splunk Enterprise or Splunk App for Infrastructure write any temporary files to /tmp/ folder (linux)?

0 Karma

qhmassc
Explorer

McAfee complains cannot find tem files like:

ERROR OASManager [6611] skipping since file path /tmp/rERp5c could not be opened due to - No such file or directory.

I am not sure who created these tmp files like rERp5c, we have Splunk Enterprise and Splunk App for Infrastructure installed with this linux server.

is there any way we can capture who is writing temporary files to /tmp folder?

0 Karma

yannK
Splunk Employee
Splunk Employee

look at the file mod time, where they created around a splunk restart when the apps were installed?

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...