Does Splunk Universal Forwarder forward audit event logs to Splunk _audit index?
I can see Splunk HF's are forwarding audit events, but couldn't find which app has inputs.conf which enable reading audit logs and forward to _audit index.
May I know which app consists inputs to read and send data to _audit index in Splunk?
You would see default/outputs.conf on the SplunkForwarder app with
[tcpout]
forwardedindex.x.whitelist= (_audit | _introspection | _telemetry)
This would forward all the _* logs to index layer.
Hi ankithreddy777
they are in system/default
and/or system/local
.
Bye.
Giuseppe
Hi ankithreddy777
if you're satisfied by this answer, please accept and/or upvote it.
Bye, see next time.
Giuseppe