[help] splunk and auditctl 1.5.2
Harper Mann
harper.mann at gmail.com
Wed Apr 16 05:20:15 UTC 2008
Hi Scott,
You can download a Splunk application from splunkbase.
http://www.splunkbase.com/apps/All/Availability/app:Splunk+for+Change+Management#
If you install the application in /opt/splunk/etc/bundles/change_management
it will include two scripts, rlog.sh and readlog.py. Readlog.py reads a
log file and manages previous reads and logrotate. rlog.sh pipes the log
output through ausearch and into Splunk. The rest of the files set up
inputs, example saved searches and a dashboard.
This application is preliminary and will be improved and updated over the
next few months. If you have trouble with it, post here and I'll assist.
You can also join the support maillist at Splunk, support at splunk.com, which
will also get to me.
Cheers,
Harper
Harper Mann
Product Manager
Splunk
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.fedoraproject.org/pipermail/users/attachments/20080415/0cfe978b/attachment-0001.html
More information about the users
mailing list