Security

how to setup security event logging linux

pontifor
New Member

Hi this is a setup question for compliance monitoring.

I have a linux box, so I index everything under /var/log. I need to build reports that

  • report each account login/logout
  • success or failure of login
  • activities performed
  • software installed/uninstalled

Any hints on how to processed? I think this is basic compliance reporting, maybe there are some examples somwhere?

thanks!
Stefan

Tags (2)
0 Karma
1 Solution

MarioM
Motivator

the Splunk for *nix app has most of what you looking for

View solution in original post

0 Karma

MarioM
Motivator

the Splunk for *nix app has most of what you looking for

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...