Splunking The Linux Audit System
Splunking The Linux Audit System
For my last blog we discussed a Splunk topic geared towards the Windows side of the shop
(Splunking Microsoft Windows Firewalls). So now it’s time to show some love to the Linux
admins out there. More specifically, in today’s blog we will explore some tips for gaining
insight into Linux audit logs using Splunk.
Conclusion
Hopefully this blog has peaked an interest from those Linux admins out there that were
looking for ways to gain operational and analytical value from their audit logs using Splunk.
Thanks for reading and please leave a comment or email us at info@function1.com with
any questions!
Link Credits
* https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/6...
Tags: Splunk, Security, linux, Unix, Audit