All Apps and Add-ons

Why is an ssh-login as root not tagged as "privileged" by the Unix-AddOn?

rvany
Communicator

I can see, that events containing some app-data like su, sudo are the only ones the AddOn tags as privileged. But in my opinion a remote login via ssh as root should also be tagged as privileged - i.e. by default (of course, I know i can do it myself, but as this app is somehow "the official way to bring Unix/Linux data into Splunk", this should be already done).

What is the dev's opinion?

0 Karma

Richfez
SplunkTrust
SplunkTrust

I would also tag any system that can have a remote login via ssh as root as "insecure by design." Or at least as having a broken audit trail. 🙂

Otherwise, I - though I have nothing to do with this add on - would agree with you it should be.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...