Splunk
Splunk and TA-linux_auditd – Optimizing the Florian Roth rules
This is a follow-up to my previous blog on Auditd and Splunk. That one was about Defender ATP and Proxmox and license consumption. I did not really touch the subject of a good Auditd baseline configuration.