Good afternoon,
A new year leads to new requests and I was recently asked about how we monitor users logging into Nagios and if we can forward those logs to Splunk for monitoring. Has anyone else done this? Have you found it helpful? As the years progress we are looking into more and more of the security aspect of applications.
Thanks
J
User logging and monitoring
Re: User logging and monitoring
This information would be stored in the audit log. On newer versions of XI this can be set up to send to a remote machine under Admin > System Information > Audit Log > Send to Nagios Log Server. Entering values in here will configure a rsyslog configuration file on the backend - /etc/rsyslog.d/nagiosxi-xi_auditlog.conf.
Note that you can point this to any syslog server and that it doesn't have to be an instance of Nagios Log Server.
Note that you can point this to any syslog server and that it doesn't have to be an instance of Nagios Log Server.
As of May 25th, 2018, all communications with Nagios Enterprises and its employees are covered under our new Privacy Policy.