illustrated Splunk server configuration steps I put Splunk server scripts for dispersing here Splunk >> bin >> scripts sudo nano /Applications/Splunk/bin/scripts/Example_OD.sh Script input: #!/bin/bash sudo log stream --level info --style syslog # trying json sudo log stream --level info --style syslog Forwarder Management: Settings >> Forwarder management Settings >> … Continue reading Open Directory audit log data into Splunk
jamf-pro config list sudo jamf-pro server restart Link to MySQL setup https://www.jamf.com/jamf-nation/articles/631/creating-the-jamf-pro-database-using-the-jamf-pro-server-tools-command-line-interface
How I poll Cisco switch syslog data at home Settings >>Data>> Data Inputs >> UDP
My mini is freezing and I am having to reboot every 12 hours, since I installed Aplunk server I want to look at those logs cd /Applications/Splunk/var/log/splunk and I am looking for splunkd.log here: /Applications/Splunk/var/log/splunk/splunkd.log
Lately when I install the client forwarder on MacOS the password gets corrupted and I have to inexplicably reset the password following this method rename the $SPLUNKHOME/etc/passswd and restart splunkforwarder to rest it to default "changeme".
Sample commands The commands in this article work with Apple Remote Desktop 3.2 and later. Here are commands that you can use: Restart the ARD Agent and helper: sudo /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -restart -agent Turn on Remote Desktop Sharing, allow access for all users, and enable the menu extra: sudo /System/Library/CoreServices/RemoteManagement/ARDAgent.app/Contents/Resources/kickstart -activate -configure -allowAccessFor -allUsers -privs -all … Continue reading Start Apple Remote Desktop
sudo softwareupdate -i -a sudo softwareupdate -l Shows pending updates sudo softwareupdate -d downloads but will not update Thanks to birchtree.me for posting this: https://birchtree.me/blog/install-mac-app-store-updates-with-one-line-in-the-terminal/