[help] splunk and auditctl 1.5.2

Harper Mann harper.mann at gmail.com
Wed Apr 16 05:20:15 UTC 2008


Hi Scott,
You can download a Splunk application from splunkbase.
http://www.splunkbase.com/apps/All/Availability/app:Splunk+for+Change+Management#
If you install the application in /opt/splunk/etc/bundles/change_management
it will include  two scripts, rlog.sh and readlog.py.  Readlog.py reads a
log file and manages previous reads and logrotate.  rlog.sh pipes the log
output through ausearch and into Splunk.  The rest of the files set up
inputs, example saved searches and a dashboard.

This application is preliminary and will be improved and updated over the
next few months.  If you have trouble with it, post here and I'll assist.
You can also join the support maillist at Splunk, support at splunk.com, which
will also get to me.

Cheers,
Harper

Harper Mann
Product Manager
Splunk
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.fedoraproject.org/pipermail/users/attachments/20080415/0cfe978b/attachment-0001.html 


More information about the users mailing list