Splunk Search

How do I extract data from this aide output

daniel333
Builder

All,

I had originally handles this with HUGE pile if SED commands and loops in a BASH script. But I am thinking there has to be a "Splunk" way of extracting these field.

Start timestamp: 2016-06-11 01:53:00
Summary:
  Total number of files:    1116
  Added files:          0
  Removed files:        1
  Changed files:        3
---------------------------------------------------
Removed files:
---------------------------------------------------
removed: /var/log/aide/aideCIM.log
---------------------------------------------------
Changed files:
---------------------------------------------------
changed: /var/log/aide
changed: /var/log/aide/aide.log
changed: /var/log/aide/aide_files.log
---------------------------------------------------
Detailed information about changes:
---------------------------------------------------
Directory: /var/log/aide
 Size     : 60                               , 42
File: /var/log/aide/aide.log
 Inode    : 203813062                        , 203815353
File: /var/log/aide/aide_files.log
 Size     : 8241                             , 6287
 Perm     : -rw-r--r--                       , -rw-------
 Inode    : 203813077                        , 203813089
 ACL      : old = A:
----
user::rw-
group::r--
other::r--
----
                  😧 <NONE>
            new = A:
----
user::rw-
group::---
other::---
----
                  😧 <NONE>

The area the challenges me the most is the multiple "changed" in a single log file. And of course the detail area. Any recommendations? Starting points.

0 Karma

saravanan90
Contributor

There  is an option in aide to get the logs in syslog format (in a single line). Please add the below lines in aide.conf. 

syslog_format = true

report_url=syslog:LOG_AUTH

 

In man pages about aide.conf

syslog_format
Valid values are yes,true,no and false. This option enables new syslog format which is suitable for logging. Every change is logged as one simple
line. This option changes verbose level to 0 and prints everything that was changed. It is suggested to use this option with "report_url=syslog:...".
Default value is "false/no". Maximum size of message is 1KB which is limitation of syslog call. If message is greater than limit, message will be
truncated. Option summarize_changes has no impact for this format.

Output always starts with:
"AIDE found differences between database and filesystem!!"
And it is followed by summary:
summary;total_number_of_files=1000;added_files=0;removed_files=0;changed_files=1
And finally there are logs about changes:
dir=/usr/sbin;Mtime_old=0000-00-00 00:00:00;Mtime_new=0000-00-00 00:00:00;...

0 Karma

ryanoconnor
Builder

Do you have any control over the output of this script? Is this something custom you are running?

0 Karma

woodcock
Esteemed Legend

It depends on what you need to do with the information in the log. What do you need out of it and how are you planning to use it?

daniel333
Builder

Good point, I was trying to do everything. I went in and shrunk down my needs. SEDCMD's all the junk that I don't want. Thanks for the wake up there.

0 Karma
Get Updates on the Splunk Community!

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...