I have multisite environment and I want to monitor all the ssh user commands through .bash_history.
for that purpose I enable the monitor:// stanza in all splunk components. interestingly, I am seeing bash_history logs from some servers and majority of the servers are not showing me logs whereas the same configuraiton is across the border.
please advise.
Hello @raiqbal47010
have you followed best practices for bash_history ingestion?
Based on this great post https://www.duanewaddle.com/splunking-bash-history/ by @dwaddle
Hello @raiqbal47010
have you followed best practices for bash_history ingestion?
Based on this great post https://www.duanewaddle.com/splunking-bash-history/ by @dwaddle
I am getting below error on splunk instances:
not exporting configurations globally to system.
and seondly no commonds shown up when I press up arrown OR down arrow. even no history when i give history command. ?