Splunk Search

Linux mounting/unmounting

mvitullo
New Member

I am attempting to create a search string for a Linux box which involves mounting/unmounting removable media devices (ie., CDs and USB devices) Any help would be welcome.

Tags (2)
0 Karma

marycordova
SplunkTrust
SplunkTrust

What you need to do is perform some stimulus response testing and development.

  1. ask the admin what linux distro and version they are running
  2. setup a vm for the distro and install a universal forwarder on it
  3. forward the logs to splunk enterprise (can be local install to your laptop/workstation where the vm is or wherever you have a splunk enterprise instance available for this dev work)
  4. perform the actions you want to write and alert for - plug in usbs, mount cds, etc
  5. look at the raw logs and write your alerts, during your analysis you might be able to generalize the alert such that it can be applied to more than one linux distro (would still require testing and validation)
  6. perhaps install the *nix app/ta to get some quick win parsing before starting the log analysis

You might also try the splunk security essentials app on splunk base, it might have some of this built already and you could just copy the searches, you would still likely benefit from testing it against a vm with proper disto.

@marycordova
0 Karma

richgalloway
SplunkTrust
SplunkTrust

It's not clear what you seek. Please explain your use case.

---
If this reply helps you, Karma would be appreciated.
0 Karma

mvitullo
New Member

I have a system admininistrator who requires a dashboard for their Linux OS. This dashboard is to be used for providing when any users place (mount) and/or remove (unmount) any form of removable media from the machine. The search string would look for any events where this would occur.

0 Karma

mlinde
Explorer

Couple questions up front:
1. Do you already collect logs on these linux systems?
2. Are you forwarding these logs into splunk already?
3. What variations of Linux are you looking to report against?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...