Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

not receiving logs from auditd enabled linux server

$
0
0
Hi everyone, to collect auditd logs from /var/log/audit.log, I just add TA-auditd and removed standard unix TA. the default TA-auditd does not have any inputs.conf file. there are no logs i check with index=* sourcetype= linux:audit whereas I can see in _internal index that events are coming.

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>