Getting Data In

add monitor "Mountain Lion Security Logs"

sterling_edmund
Explorer

How would you log the new Apple Security Logs in Mountain Lion 10.8. Thanks

Tags (1)

jbsplunk
Splunk Employee
Splunk Employee

In 10.8, data is logged to asl(syslog) instead of secure.log, so it would be something like this:

./splunk add monitor /var/log/asl

jbsplunk
Splunk Employee
Splunk Employee

I just checked mine, and the data appears to be binary. So Splunk isn't going to read it. You could send NO_BINARY_CHECK to process the files using props.conf though.

0 Karma

sterling_edmund
Explorer



0/s:key
118660/s:key
/var/log/asl/s:key
0.00/s:key
unreadable file type/s:key
/s:dict
/s:key

0 Karma

sterling_edmund
Explorer

checking thanks

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

From $SPLUNK_HOME/bin you can run 'splunk _internal call /services/admin/inputstatus/TailingProcessor:FileStatus > output' and then search output for the files in ASL, it'll tell you why they're ignored or if they've been read.

0 Karma

sterling_edmund
Explorer

Still does not read the asl files - wip - thanks

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...