Splunk Enterprise Security

Can you help me understand why my /var/log/secure useradd field extractions are not working as expected?

daniel333
Builder

All,

I have a clean install of Splunk ES with the latest Splunk App For Nix enabled. The Account Management dashboard is not populating in a useful.

I have this log event which is my test -
Apr 10 19:44:10 myhost useradd[5965]: new user: name=mysql, UID=997, GID=994, home=/var/lib/mysql, shell=/bin/bash

SHOULD pull field extraction from this out of the box transform stanza -

[useradd]
REGEX = .*?((new) (user|group|account))(?:: | (?:added) - )(?:name|account)=(\w+),
FORMAT = vendor_action::$1 object_category::$3 name::$4 user::$4

I confirmed you stanza SHOULD work in regex101.com

Can you help me understand why this isn't working as I expect? I believe users added, removed, groups added, removed should appear here by who executed the command.

0 Karma

p_gurav
Champion

Can you also verify the sourcetype name in both application and in normal search? Also try running dashboard search manually and check which parameter is not match.

0 Karma

FrankVl
Ultra Champion

Also: the account management dashboard probably relies on the Change Analysis data model. So you may want to check if that is being populated correctly.

0 Karma

daniel333
Builder

Ended up finding the default lookup tables were missing entries for my OS. Aftermanually adding them I was set. Send in the missing elements to support to maybe they'll make their way into the next release.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...