<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Detecting removable media in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/Detecting-removable-media/m-p/46096#M1368</link>
    <description>&lt;P&gt;Thanks R.Turk, &lt;/P&gt;

&lt;P&gt;I guess the first one is the simpler way, I just need to figure out the search patterns.&lt;/P&gt;</description>
    <pubDate>Fri, 30 Aug 2013 08:32:26 GMT</pubDate>
    <dc:creator>malex27</dc:creator>
    <dc:date>2013-08-30T08:32:26Z</dc:date>
    <item>
      <title>Detecting removable media</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Detecting-removable-media/m-p/46094#M1366</link>
      <description>&lt;P&gt;I need to detect when a removable media (USB stick, CD, external disks, ...) is attached or detached to our Linux servers. &lt;/P&gt;

&lt;P&gt;Anyone implemented it?&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Alessio&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2013 13:37:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Detecting-removable-media/m-p/46094#M1366</guid>
      <dc:creator>malex27</dc:creator>
      <dc:date>2013-08-26T13:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: Detecting removable media</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Detecting-removable-media/m-p/46095#M1367</link>
      <description>&lt;P&gt;Hi Malex27,&lt;/P&gt;

&lt;P&gt;Typically, linux will write an entry into:&lt;BR /&gt;
    /var/log/messages&lt;/P&gt;

&lt;P&gt;Whenever a USB device is plugged in or removed from the server. You can configure this to be manually monitored via a &lt;STRONG&gt;monitor&lt;/STRONG&gt; stanza in your inputs.conf.&lt;/P&gt;

&lt;P&gt;Alternatively, you can use the &lt;A href="http://apps.splunk.com/app/273"&gt;Splunk for Unix &amp;amp; Linux&lt;/A&gt; app to monitor the file and send the data to an Indexer for the purposes of reporting.&lt;/P&gt;

&lt;P&gt;Hope this helps &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2013 13:43:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Detecting-removable-media/m-p/46095#M1367</guid>
      <dc:creator>rturk</dc:creator>
      <dc:date>2013-08-26T13:43:44Z</dc:date>
    </item>
    <item>
      <title>Re: Detecting removable media</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/Detecting-removable-media/m-p/46096#M1368</link>
      <description>&lt;P&gt;Thanks R.Turk, &lt;/P&gt;

&lt;P&gt;I guess the first one is the simpler way, I just need to figure out the search patterns.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Aug 2013 08:32:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/Detecting-removable-media/m-p/46096#M1368</guid>
      <dc:creator>malex27</dc:creator>
      <dc:date>2013-08-30T08:32:26Z</dc:date>
    </item>
  </channel>
</rss>

