Getting Data In

Does Splunk Universal Forwarder forward audit events

ankithreddy777
Contributor

Does Splunk Universal Forwarder forward audit event logs to Splunk _audit index?
I can see Splunk HF's are forwarding audit events, but couldn't find which app has inputs.conf which enable reading audit logs and forward to _audit index.

May I know which app consists inputs to read and send data to _audit index in Splunk?

0 Karma

lakshman239
Influencer

You would see default/outputs.conf on the SplunkForwarder app with

[tcpout]
forwardedindex.x.whitelist= (_audit | _introspection | _telemetry)

This would forward all the _* logs to index layer.

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi ankithreddy777
they are in system/default and/or system/local.
Bye.
Giuseppe

gcusello
SplunkTrust
SplunkTrust

Hi ankithreddy777
if you're satisfied by this answer, please accept and/or upvote it.

Bye, see next time.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...