Splunk Search

Linux mounting/unmounting

mvitullo
New Member

I am attempting to create a search string for a Linux box which involves mounting/unmounting removable media devices (ie., CDs and USB devices) Any help would be welcome.

Tags (2)
0 Karma

marycordova
SplunkTrust
SplunkTrust

What you need to do is perform some stimulus response testing and development.

  1. ask the admin what linux distro and version they are running
  2. setup a vm for the distro and install a universal forwarder on it
  3. forward the logs to splunk enterprise (can be local install to your laptop/workstation where the vm is or wherever you have a splunk enterprise instance available for this dev work)
  4. perform the actions you want to write and alert for - plug in usbs, mount cds, etc
  5. look at the raw logs and write your alerts, during your analysis you might be able to generalize the alert such that it can be applied to more than one linux distro (would still require testing and validation)
  6. perhaps install the *nix app/ta to get some quick win parsing before starting the log analysis

You might also try the splunk security essentials app on splunk base, it might have some of this built already and you could just copy the searches, you would still likely benefit from testing it against a vm with proper disto.

@marycordova
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's not clear what you seek. Please explain your use case.

---
If this reply helps you, Karma would be appreciated.
0 Karma

mvitullo
New Member

I have a system admininistrator who requires a dashboard for their Linux OS. This dashboard is to be used for providing when any users place (mount) and/or remove (unmount) any form of removable media from the machine. The search string would look for any events where this would occur.

0 Karma

mlinde
Explorer

Couple questions up front:
1. Do you already collect logs on these linux systems?
2. Are you forwarding these logs into splunk already?
3. What variations of Linux are you looking to report against?

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...