Quantcast
Viewing all articles
Browse latest Browse all 47296

Process Solaris audit files into Splunk 7.2.5

Hi, I have a customer running both Solaris 11 and I need to monitor their Solaris audit data as kept in their Global Zones (this monitors all Zones). How do I process this binary format file to retrieve only the latest log file (same way that DB-Connect App does). I have TA for *NIX LINUX installed on their Splunk Server. I want to be able to retrieve data such as: User Login information - failed; successfull with time of login and the number of attempts of unsuccessful logins etc. Regards David

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>