Deployment Architecture

Are there related fields between sudo log and LDAP log? I want to monitor daily Linux sudo activity.

vicky05ssr04
Engager

I have a requirement for daily report of Linux sudo activity.

I came to know that the LDAP log will tell me if the user successfully has access, and sudo log will tell me what the execute request is and where?

Can I relate both logs using a common keyword or something to fetch results of both? I don't see one. Is there any approach tried by anyone on this, please let me know asap!

0 Karma

jfraiberg
Communicator

This really depends on how you are using ldap and sudo in your environment. Do the usernames match between the 2 log sources? If they do you should be able to easily correlate the 2. If they are not the same you could create a mapping between the 2 and use a lookup table or kvstore to facilitate the correlation.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...