Advertisement
phoenixdigital

splunk-pack-nix.conf

Jan 31st, 2021
1,775
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
JSON 1.91 KB | None | 0 0
  1. {
  2.     "queries": {
  3.         "ulimit_info": {
  4.             "query": "select * from ulimit_info;",
  5.             "interval": 86400
  6.         },
  7.         "rpm_packages": {
  8.             "query": "select * from rpm_packages;",
  9.             "interval": 86400
  10.         },
  11.         "sudoers": {
  12.             "query": "select * from sudoers;",
  13.             "interval": 86400
  14.         },
  15.         "mounts": {
  16.             "query": "select * from mounts;",
  17.             "interval": 86400
  18.         },
  19.         "crontab": {
  20.             "query": "select * from crontab;",
  21.             "interval": 86400
  22.         },
  23.         "memory_info": {
  24.             "query": "select * from memory_info;",
  25.             "interval": 3600,
  26.             "removed": false
  27.         },
  28.         "mounts": {
  29.             "query": "select (select datetime from time) AS poll_time, mounts.device, mounts.device_alias, mounts.path, mounts.type, mounts.blocks_size, mounts.blocks, mounts.blocks_free, mounts.blocks_available, ((mounts.blocks_size * mounts.blocks) / (1024 * 1024)) AS mb_total, ((mounts.blocks_size * (mounts.blocks - mounts.blocks_free)) / (1024 * 1024)) AS mb_used, ((mounts.blocks_size * mounts.blocks_free) / (1024 * 1024)) AS mb_free, mounts.flags, block_devices.parent, block_devices.vendor, block_devices.model, block_devices.uuid, block_devices.type, block_devices.label from mounts LEFT JOIN block_devices ON mounts.device_alias = block_devices.name  where path NOT LIKE '/sys%' AND path NOT LIKE '/dev/%';",
  30.             "interval": 3600,
  31.             "removed": false
  32.         },
  33.         "file_events": {
  34.             "query": "SELECT file_events.*, users.username FROM file_events JOIN users ON file_events.uid = users.uid",
  35.             "interval": 300,
  36.             "removed": false
  37.         }
  38.     },
  39.     "file_paths": {
  40.         "ssh": [
  41.             "/root/.ssh/%%",
  42.             "/home/%/.ssh/%%"
  43.         ],
  44.         "userbins": [
  45.             "/home/%/bin/%%",
  46.             "/home/%/sbin/%%",
  47.             "/usr/bin/%%",
  48.             "/usr/sbin/%%",
  49.             "/usr/lib/%%",
  50.             "/usr/local/bin/%%",
  51.             "/usr/local/sbin/%%",
  52.             "/usr/local/lib/%%",
  53.             "/root/bin/%%"
  54.         ],
  55.         "etc": [
  56.             "/etc/%%"
  57.         ],
  58.         "system": [
  59.             "/bin/%%",
  60.             "/sbin/%%",
  61.             "/lib/%%",
  62.             "/boot/%%",
  63.             "/initrd/%%"
  64.         ]
  65.     }
  66. }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement