-
Story
-
Resolution: Done
-
Major
-
None
-
5
-
False
-
None
-
False
-
NEW
-
OBSDA-344 - Audit log forwarding produces excessive data, configuration for prefiltering is needed
-
NEW
-
-
-
Log Collection - Sprint 236, Log Collection - Sprint 237, Log Collection - Sprint 238, Log Collection - Sprint 239, Log Collection - Sprint 240, Log Collection - Sprint 241, Log Collection - Sprint 242
Implementation
The policy fliter is based on the existing executable filter: https://gitlab.cee.redhat.com/gsleeman/splunk-audit-exporter
The CLO filter will use a VRL transform so it can integrate smoothly with other vector-based sources, filters, transforms and sinks.
The VRL transform will be "compiled" from the policy document to implement that specific policy
It will be important to test for equivalence of output between CLO and splunk-audit-exporter across a wide range of log data.
- links to