Getting Data In

Does Splunk Universal Forwarder forward audit events

ankithreddy777
Contributor

Does Splunk Universal Forwarder forward audit event logs to Splunk _audit index?
I can see Splunk HF's are forwarding audit events, but couldn't find which app has inputs.conf which enable reading audit logs and forward to _audit index.

May I know which app consists inputs to read and send data to _audit index in Splunk?

0 Karma

lakshman239
SplunkTrust
SplunkTrust

You would see default/outputs.conf on the SplunkForwarder app with

[tcpout]
forwardedindex.x.whitelist= (_audit | _introspection | _telemetry)

This would forward all the _* logs to index layer.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi ankithreddy777
they are in system/default and/or system/local.
Bye.
Giuseppe

gcusello
SplunkTrust
SplunkTrust

Hi ankithreddy777
if you're satisfied by this answer, please accept and/or upvote it.

Bye, see next time.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...