<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can we track configuration changes on a universal forwarder server? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/How-can-we-track-configuration-changes-on-a-universal-forwarder/m-p/403595#M14556</link>
    <description>&lt;P&gt;Hello ankithreddy777,&lt;/P&gt;

&lt;P&gt;there might be an app out there, which does that. In general you would have to figure out what you can get from splunk internal and audit logs.&lt;/P&gt;

&lt;P&gt;For example you can get changes on datamodel-config with &lt;CODE&gt;index=_internal sourcetype=splunkd_access (splunk_action=disable OR splunk_action=moce OR splunk_action=enable)&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;And you could add a list of your users.&lt;/P&gt;

&lt;P&gt;Sadly there is no good documentation about the component. Not that I now of.&lt;/P&gt;

&lt;P&gt;Hope that helps.&lt;/P&gt;

&lt;P&gt;Kind Regards&lt;/P&gt;</description>
    <pubDate>Tue, 27 Nov 2018 10:47:17 GMT</pubDate>
    <dc:creator>dkeck</dc:creator>
    <dc:date>2018-11-27T10:47:17Z</dc:date>
    <item>
      <title>How can we track configuration changes on a universal forwarder server?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-can-we-track-configuration-changes-on-a-universal-forwarder/m-p/403594#M14555</link>
      <description>&lt;P&gt;We have around 1K+ universal forwarder servers where we have deployed apps manually without using DS.&lt;/P&gt;

&lt;P&gt;Is there any way to track the configuration changes (inputs.conf or outputs.conf) by any un-authorized user?&lt;/P&gt;

&lt;P&gt;One way is to use btool and get all current configurations copied to filesystem in a scheduled manner and ingest configurations to Splunk and compare them to track changes. But this approach has limitations due to license and storage for these extra logs.&lt;/P&gt;

&lt;P&gt;May I know whether there is any way to implement configuration tracking?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Nov 2018 19:53:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-can-we-track-configuration-changes-on-a-universal-forwarder/m-p/403594#M14555</guid>
      <dc:creator>ankithreddy777</dc:creator>
      <dc:date>2018-11-26T19:53:43Z</dc:date>
    </item>
    <item>
      <title>Re: How can we track configuration changes on a universal forwarder server?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-can-we-track-configuration-changes-on-a-universal-forwarder/m-p/403595#M14556</link>
      <description>&lt;P&gt;Hello ankithreddy777,&lt;/P&gt;

&lt;P&gt;there might be an app out there, which does that. In general you would have to figure out what you can get from splunk internal and audit logs.&lt;/P&gt;

&lt;P&gt;For example you can get changes on datamodel-config with &lt;CODE&gt;index=_internal sourcetype=splunkd_access (splunk_action=disable OR splunk_action=moce OR splunk_action=enable)&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;And you could add a list of your users.&lt;/P&gt;

&lt;P&gt;Sadly there is no good documentation about the component. Not that I now of.&lt;/P&gt;

&lt;P&gt;Hope that helps.&lt;/P&gt;

&lt;P&gt;Kind Regards&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 10:47:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-can-we-track-configuration-changes-on-a-universal-forwarder/m-p/403595#M14556</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2018-11-27T10:47:17Z</dc:date>
    </item>
    <item>
      <title>Re: How can we track configuration changes on a universal forwarder server?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-can-we-track-configuration-changes-on-a-universal-forwarder/m-p/403596#M14557</link>
      <description>&lt;P&gt;please accept answer if it was helpful &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Dec 2018 08:46:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-can-we-track-configuration-changes-on-a-universal-forwarder/m-p/403596#M14557</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2018-12-06T08:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: How can we track configuration changes on a universal forwarder server?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-can-we-track-configuration-changes-on-a-universal-forwarder/m-p/573434#M24997</link>
      <description>&lt;P&gt;Replying to this old post as it's high in the returned search engine results.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splunk 8.2 now tracks configuration file changes if enabled as per&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/WhatSplunklogsaboutitself#Internal_logs" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/WhatSplunklogsaboutitself#Internal_logs&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Refer to configuration_change.log&lt;/P&gt;&lt;P&gt;The current version only advises the file has changed but this may improve in future releases.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 06:22:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-can-we-track-configuration-changes-on-a-universal-forwarder/m-p/573434#M24997</guid>
      <dc:creator>gjanders</dc:creator>
      <dc:date>2021-11-03T06:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: How can we track configuration changes on a universal forwarder server?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-can-we-track-configuration-changes-on-a-universal-forwarder/m-p/573444#M24999</link>
      <description>&lt;P&gt;Nice to know. Now that could be a nice trigger for a pull the config from the affected machine and push it into VCS...&lt;/P&gt;</description>
      <pubDate>Wed, 03 Nov 2021 07:07:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-can-we-track-configuration-changes-on-a-universal-forwarder/m-p/573444#M24999</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-03T07:07:17Z</dc:date>
    </item>
  </channel>
</rss>

