Auditd
Auditd-related search macros, datamodel queries, transformations and configurations
Last updated
Auditd-related search macros, datamodel queries, transformations and configurations
Last updated
| rex field = msg "(?<unixtime>\\d{10}\.\\d{3})"
| rex field = msg ":(?<msg_id>\\d{6})"
| eval readable_time = strftime(unixtime, "%Y-%m-%d %H:%M:%S.%Q")| eval process_title = urldecode(replace(proctitle,"([0-9A-F]{2})","%\1"))index = auditd
| search [
index = auditd
| search key = <key_name>
| fields msg
| format ]