Monitoring Splunk

Splunk generating tons of fcntl Solaris audit records

dcarlo
New Member

I have a Solaris 10 SPARC server that is running Splunk 4.1. It's configured to generate audit logs to syslog, create local log files, and Splunk is configured to forward them to a central Splunk server. The problem that I'm having is that Splunk is generating thousands of audit records per minute. They are all fcntl system calls. Here's an example record from praudit:

header,168,2,fcntl(2),,unixhost,2010-07-07 08:01:46.018 -04:00,argument,2,0x3,cmd,argument,1,0x16,no path: fd,attribute,140666,root,root,331,48471,0,subject,localuser,splunk,splunk,splunk,splunk,1343,1687751497,15720 196630 192.168.99.5,return,success,2,zone,global,sequence,4773104,trailer,168

Has anybody seen this?

--Dave

Tags (1)
0 Karma

gkanapathy
Splunk Employee
Splunk Employee

I suppose one question is what your BSM system is set up to audit. It's entirely normal for Splunk to be reading and writing many files a lot (that is it's purpose) and thousands of reads and writes per minute doesn't seem unreasonable, but it depends on whether these are files it is supposed to be reading and writing.

Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...