Re: [help] splunk and auditctl 1.5.2

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi Scott,
You can download a Splunk application from splunkbase.
http://www.splunkbase.com/apps/All/Availability/app:Splunk+for+Change+Management#
If you install the application in /opt/splunk/etc/bundles/change_management it will include  two scripts, rlog.sh and readlog.py.  Readlog.py reads a log file and manages previous reads and logrotate.  rlog.sh pipes the log output through ausearch and into Splunk.  The rest of the files set up inputs, example saved searches and a dashboard.

This application is preliminary and will be improved and updated over the next few months.  If you have trouble with it, post here and I'll assist.  You can also join the support maillist at Splunk, support@xxxxxxxxxx, which will also get to me.

Cheers,
Harper

Harper Mann
Product Manager
Splunk



[Index of Archives]     [Current Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Yosemite News]     [Yosemite Photos]     [KDE Users]     [Fedora Tools]     [Fedora Docs]

  Powered by Linux