Files
splunk-security_content/data_sources/linux_secure.yml
T
2024-07-31 09:58:03 +02:00

48 lines
759 B
YAML

name: Linux Secure
id: 9a47d88b-1b17-49ce-a0ef-b440ddbd98bb
version: 1
date: '2024-07-18'
author: Patrick Bareiss, Splunk
description: Data source object for Linux Secure
source: /var/log/secure
sourcetype: linux_secure
supported_TA: []
fields:
- _time
- action
- app
- date_hour
- date_mday
- date_minute
- date_month
- date_second
- date_wday
- date_year
- date_zone
- dest
- dvc
- eventtype
- host
- index
- linecount
- pid
- process
- punct
- source
- sourcetype
- splunk_server
- src
- src_port
- sshd_protocol
- tag
- tag::action
- tag::eventtype
- timeendpos
- timestartpos
- user
- user_name
- vendor_action
- vendor_product
example_log: 'May 27 09:28:36 ip-172-31-24-46 sshd[5617]: Accepted password for mikael
from 84.202.159.161 port 63487 ssh2'