<?xml version="1.0" ?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
	<channel>
		<title>Splunk Base : SplunkAdministration : #3420</title>
		<link>http://www.splunk.com/support/forum:SplunkAdministration/3420</link>
		<description></description>
		<pubDate>Mon, 13 Feb 2012 19:24:26 PST</pubDate>
		<lastBuildDate>Mon, 13 Feb 2012 19:24:26 PST</lastBuildDate>
		<language>en-us</language>
		<copyright>http://creativecommons.org/licenses/by-nc-nd/2.5/</copyright>
		<item>
			<title>Problem to Index Linux Auditd</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3420/12795</link>
			<description>&lt;p&gt;OK cracked it&lt;/p&gt;

&lt;p&gt;Not sure if i's a bug or not but I was configuring the tcp port vi a the data inputs link on the mgmt links on the receiver - just did it through the set up Forwarders and Receivers tab instead and it worked straight away.&lt;/p&gt;

</description>
			<pubDate>Mon, 25 Jan 2010 08:16:31 PST</pubDate>
			<author>splunkles99</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3420/12795</guid>
		</item>
		<item>
			<title>Problem to Index Linux Auditd</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3420/12792</link>
			<description>&lt;p&gt;Yep the index is there and I have mapped the admin user to it. I log on with the admin user account, but there is no data in the index to search as it's all in the main index - so that proves all comnnectivity is working - I can generate the logs - snoop the interface - see the data getting into the mainindex - view the data in the main index but I want it in the devidx index.&lt;/p&gt;

&lt;p&gt;What I'm trying to achieve is logging all data forwarded from a remote  /var/log/ to a specific index - I don't think routing specific events to specific queues is what I'm after but will take a look - thanks&lt;/p&gt;

</description>
			<pubDate>Mon, 25 Jan 2010 06:29:55 PST</pubDate>
			<author>splunkles99</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3420/12792</guid>
		</item>
		<item>
			<title>Problem to Index Linux Auditd</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3420/12713</link>
			<description>&lt;p&gt;&lt;a href=&quot;http://www.splunk.com/base/Documentation/latest/Admin/Routeeventstospecificqueues&quot;&gt;http://www.splunk.com/base/Documentation/latest/Admin/Routeeventstospecificqueues&lt;/a&gt;&lt;/p&gt;

</description>
			<pubDate>Tue, 19 Jan 2010 20:26:01 PST</pubDate>
			<author>gkanapathy</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3420/12713</guid>
		</item>
		<item>
			<title>Problem to Index Linux Auditd</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3420/12706</link>
			<description>&lt;p&gt;Have you&lt;br /&gt;
 * created the new index on the indexer&lt;br /&gt;
 * set your user role to be allowed and/or to default to search the new index?&lt;/p&gt;

</description>
			<pubDate>Tue, 19 Jan 2010 20:09:27 PST</pubDate>
			<author>gkanapathy</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3420/12706</guid>
		</item>
		<item>
			<title>Problem to Index Linux Auditd</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3420/12690</link>
			<description>&lt;p&gt;can you post you inputs.conf - I'm having similar issues - I can forward data from my splunklightforwarder to a port on the indexer but it's not going to the index i set in the inputs.conf using&lt;/p&gt;

&lt;p&gt;[monitor:///usr/local/apache2/logs/]&lt;br /&gt;
apache logs /usr/local/apache2/logs/&lt;br /&gt;
index = devidx&lt;br /&gt;
disabled = false&lt;br /&gt;
host = devhost&lt;/p&gt;

&lt;p&gt;I can view the data in the main index but not my devidx&lt;/p&gt;

</description>
			<pubDate>Tue, 19 Jan 2010 07:24:06 PST</pubDate>
			<author>splunkles99</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3420/12690</guid>
		</item>
		<item>
			<title>Problem to Index Linux Auditd</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3420/11112</link>
			<description>&lt;p&gt;Great to hear!&lt;/p&gt;

</description>
			<pubDate>Thu, 15 Oct 2009 07:48:46 PDT</pubDate>
			<author>araitz</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3420/11112</guid>
		</item>
		<item>
			<title>Problem to Index Linux Auditd</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3420/11111</link>
			<description>&lt;p&gt;Araitz. I resolved the problem.&lt;br /&gt;
I configured my inputs.conf in the Apps&lt;/p&gt;

&lt;p&gt;&amp;quot;opt/splunk/etc/apps/search/local/inputs.conf&amp;quot;&lt;/p&gt;

&lt;p&gt;I added the index parameters to indicate what index has to go the data.&lt;br /&gt;
I think the problem was the splunk started using the main index by default and auto set the sourcetype=linux_auditt&lt;/p&gt;

&lt;p&gt;Now It's indexing on the OS index and using the sourcetype=audit.log and show all the events or at least the most important.&lt;/p&gt;

&lt;p&gt;thanks for your help.&lt;/p&gt;

</description>
			<pubDate>Thu, 15 Oct 2009 04:54:24 PDT</pubDate>
			<author>apardo</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3420/11111</guid>
		</item>
		<item>
			<title>Problem to Index Linux Auditd</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3420/11105</link>
			<description>&lt;p&gt;I'm looking for the inputs.conf that tells the forwarder which files to monitor, but I wouldn't worry about that at the moment.&lt;/p&gt;

&lt;p&gt;What search are you running on the indexer that shows you only 3 of 5 lines?  What is the time picker set to?  If you want, you can upload a screenshot to www.imagebin.ca and post the link to it here.&lt;/p&gt;

</description>
			<pubDate>Wed, 14 Oct 2009 15:17:13 PDT</pubDate>
			<author>araitz</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3420/11105</guid>
		</item>
		<item>
			<title>Problem to Index Linux Auditd</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3420/11103</link>
			<description>&lt;p&gt;the /opt/splunk/etc/system/local/inputs.conf&lt;/p&gt;

&lt;p&gt;[default]&lt;br /&gt;
host = centos4&lt;/p&gt;

&lt;p&gt;the  /opt/splunk/etc/system/default/inputs.conf&lt;/p&gt;

&lt;ol&gt;
    &lt;li&gt;Copyright (C) 2005-2009 Splunk Inc.  All Rights Reserved.  Version 4.0&lt;/li&gt;
    &lt;li&gt;DO NOT EDIT THIS FILE!&lt;/li&gt;
    &lt;li&gt;Please make all changes to files in $SPLUNK_HOME/etc/system/local.&lt;/li&gt;
    &lt;li&gt;To make changes, copy the section/stanza you want to change from $SPLUNK_HOME/etc/system/default&lt;/li&gt;
    &lt;li&gt;into ../local and edit there.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;#&lt;/p&gt;

&lt;ol&gt;
    &lt;li&gt;This file contains possible attributes and values you can use to&lt;/li&gt;
    &lt;li&gt;configure inputs, distributed inputs and file system monitoring.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;[default]&lt;br /&gt;
index         = default&lt;br /&gt;
host          = localhost&lt;br /&gt;
_rcvbuf        = 1572864&lt;/p&gt;

&lt;p&gt;[monitor:&lt;em&gt;$SPLUNK_HOME/var/log/splunk]&lt;br /&gt;
index = _internal&lt;/p&gt;

&lt;p&gt;[batch:&lt;/em&gt;$SPLUNK_HOME/var/spool/splunk]&lt;br /&gt;
move_policy = sinkhole&lt;br /&gt;
crcSalt = &amp;lt;SOURCE&amp;gt;&lt;/p&gt;

&lt;p&gt;[fschange:$SPLUNK_HOME/etc]&lt;br /&gt;
#poll every 10 minutes&lt;br /&gt;
pollPeriod = 600&lt;br /&gt;
#generate audit events into the audit index, instead of fschange events&lt;br /&gt;
signedaudit=true&lt;br /&gt;
recurse=true&lt;br /&gt;
followLinks=false&lt;br /&gt;
hashMaxSize=-1&lt;br /&gt;
fullEvent=false&lt;br /&gt;
sendEventMaxSize=-1&lt;br /&gt;
filesPerDelay = 10&lt;br /&gt;
delayInMills = 100&lt;/p&gt;

&lt;p&gt;[splunktcp]&lt;br /&gt;
route=has_key:_utf8:indexQueue;has_key:_linebreaker:indexQueue;absent_key:_utf8:parsingQueue;absent_key:_linebreaker:parsingQueue&lt;/p&gt;

&lt;p&gt;[SSL]&lt;/p&gt;

&lt;ol&gt;
    &lt;li&gt;default cipher suites that splunk allows. Change this if you wish to increase the security&lt;/li&gt;
    &lt;li&gt;of SSL connections, or to lower it if you having trouble connecting to splunk.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;cipherSuite = ALL:!aNULL:!eNULL:!LOW:!EXP:RC4+RSA:+HIGH:+MEDIUM&lt;/p&gt;

</description>
			<pubDate>Wed, 14 Oct 2009 12:52:41 PDT</pubDate>
			<author>apardo</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3420/11103</guid>
		</item>
		<item>
			<title>Problem to Index Linux Auditd</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3420/11101</link>
			<description>&lt;p&gt;Please tell me the path of the inputs.conf&lt;/p&gt;

</description>
			<pubDate>Wed, 14 Oct 2009 12:03:08 PDT</pubDate>
			<author>apardo</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3420/11101</guid>
		</item>
		<item>
			<title>Problem to Index Linux Auditd</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3420/11099</link>
			<description>&lt;p&gt;What does your inputs.conf look like on the forwarder?&lt;/p&gt;

</description>
			<pubDate>Wed, 14 Oct 2009 11:10:59 PDT</pubDate>
			<author>araitz</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3420/11099</guid>
		</item>
		<item>
			<title>Problem to Index Linux Auditd</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/3420/11098</link>
			<description>&lt;p&gt;Hi everyone.&lt;/p&gt;

&lt;p&gt;I have some problems to get full index some linux audit log.&lt;br /&gt;
I set a light forwarder server to report they /var/log/audit/audit.log to the central server.&lt;/p&gt;

&lt;p&gt;The forwarder show in the log file the normal lines &lt;br /&gt;
example /var/log/audit/audit.log&lt;/p&gt;

&lt;p&gt;type=PATH msg=audit(1255538594.639:261): name=&amp;quot;/etc/file6&amp;quot; flags=310 inode=473281 dev=fd:00 mode=040755 ouid=0 ogid=0 rdev=00:00&lt;br /&gt;
type=CWD msg=audit(1255538594.639:261):  cwd=&amp;quot;/root&amp;quot;&lt;br /&gt;
type=FS_INODE msg=audit(1255538594.639:261): inode=473281 inode_uid=0 inode_gid=0 inode_dev=fd:00 inode_rdev=00:00&lt;br /&gt;
type=FS_WATCH msg=audit(1255538594.639:261): watch_inode=473281 watch=&amp;quot;etc&amp;quot; filterkey=etc perm=2 perm_mask=3&lt;br /&gt;
type=SYSCALL msg=audit(1255538594.639:261): arch=40000003 syscall=5 success=yes exit=3 a0=bff6fc4b a1=8941 a2=1b6 a3=8941 items=1 pid=16375 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 comm=&amp;quot;touch&amp;quot; exe=&amp;quot;/bin/touch&amp;quot;&lt;/p&gt;

&lt;p&gt;but the Central Splunk just show me 3 of 5 lines.&lt;/p&gt;

&lt;p&gt;type=CWD msg=audit(1255538594.639:261):  cwd=&amp;quot;/root&amp;quot;&lt;br /&gt;
type=FS_WATCH msg=audit(1255538594.639:261): watch_inode=473281 watch=&amp;quot;etc&amp;quot; filterkey=etc perm=2 perm_mask=3&lt;br /&gt;
type=SYSCALL msg=audit(1255538594.639:261): arch=40000003 syscall=5 success=yes exit=3 a0=bff6fc4b a1=8941 a2=1b6 a3=8941 items=1 pid=16375 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 comm=&amp;quot;touch&amp;quot; exe=&amp;quot;/bin/touch&amp;quot;&lt;/p&gt;

&lt;p&gt;I don't know what to touch to allow to index the full log and not partially. BTW When I index a off line file as /var/log/audit/audit.1.log show me all the content.&lt;/p&gt;

&lt;p&gt;my best regards for any help on this one.&lt;/p&gt;

&lt;p&gt;Alvaro Pardo&lt;/p&gt;

</description>
			<pubDate>Wed, 14 Oct 2009 10:09:35 PDT</pubDate>
			<author>apardo</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/3420/11098</guid>
		</item>
	</channel>
</rss>

