<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitor Who has made a change to a file in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-Who-has-made-a-change-to-a-file/m-p/97856#M20405</link>
    <description>&lt;P&gt;You'll probably need to set up the auditing functions for your OS in question. (Typically &lt;CODE&gt;auditd&lt;/CODE&gt; for Linux and enabling the &lt;CODE&gt;Object Access&lt;/CODE&gt; audit policy on Windows). &lt;/P&gt;

&lt;P&gt;Splunk used to have a function for this, well it's actually still there, but it's been deprecated in version 5.x. This solution (fschangemonitor) can not however detect WHO made changes to a file. &lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;/P&gt;

&lt;P&gt;Kristian&lt;/P&gt;</description>
    <pubDate>Wed, 17 Apr 2013 14:50:17 GMT</pubDate>
    <dc:creator>kristian_kolb</dc:creator>
    <dc:date>2013-04-17T14:50:17Z</dc:date>
    <item>
      <title>Monitor Who has made a change to a file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-Who-has-made-a-change-to-a-file/m-p/97855#M20404</link>
      <description>&lt;P&gt;Hey Guys &lt;/P&gt;

&lt;P&gt;A simple one for someone out there im sure, I have a file on 3 servers that I currently monitor the changes to with Splunk, I have been asked to monitor the said files for the change and also the user account that makes the change, can anyone advise on how to do this ?&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2013 14:39:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-Who-has-made-a-change-to-a-file/m-p/97855#M20404</guid>
      <dc:creator>AaronMoorcroft</dc:creator>
      <dc:date>2013-04-17T14:39:25Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Who has made a change to a file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-Who-has-made-a-change-to-a-file/m-p/97856#M20405</link>
      <description>&lt;P&gt;You'll probably need to set up the auditing functions for your OS in question. (Typically &lt;CODE&gt;auditd&lt;/CODE&gt; for Linux and enabling the &lt;CODE&gt;Object Access&lt;/CODE&gt; audit policy on Windows). &lt;/P&gt;

&lt;P&gt;Splunk used to have a function for this, well it's actually still there, but it's been deprecated in version 5.x. This solution (fschangemonitor) can not however detect WHO made changes to a file. &lt;/P&gt;

&lt;P&gt;Hope this helps,&lt;/P&gt;

&lt;P&gt;Kristian&lt;/P&gt;</description>
      <pubDate>Wed, 17 Apr 2013 14:50:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-Who-has-made-a-change-to-a-file/m-p/97856#M20405</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-04-17T14:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Who has made a change to a file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-Who-has-made-a-change-to-a-file/m-p/97857#M20406</link>
      <description>&lt;P&gt;thats a great help, thanks for your advice.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2013 07:50:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-Who-has-made-a-change-to-a-file/m-p/97857#M20406</guid>
      <dc:creator>AaronMoorcroft</dc:creator>
      <dc:date>2013-04-18T07:50:52Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Who has made a change to a file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-Who-has-made-a-change-to-a-file/m-p/97858#M20407</link>
      <description>&lt;P&gt;can splunk detect which line of the file was change and what was the changes like what the diff command does?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2013 16:19:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-Who-has-made-a-change-to-a-file/m-p/97858#M20407</guid>
      <dc:creator>necrophobic</dc:creator>
      <dc:date>2013-10-16T16:19:38Z</dc:date>
    </item>
    <item>
      <title>Re: Monitor Who has made a change to a file</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitor-Who-has-made-a-change-to-a-file/m-p/97859#M20408</link>
      <description>&lt;P&gt;Well, I believe that there is/was an optional attribute called &lt;CODE&gt;fullEvent&lt;/CODE&gt; (boolean), that would toggle whether splunk should index the contents of the file being audited. &lt;/P&gt;

&lt;P&gt;If I remember correctly this did not really work all that well when I tried it last - on &lt;CODE&gt;*&lt;/CODE&gt;nix the whole file came in as one event, and on Windows, each line of the file became a separate event (or if it was the other way round). But this was back in the 4.x days...&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2013 19:59:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitor-Who-has-made-a-change-to-a-file/m-p/97859#M20408</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2013-10-17T19:59:46Z</dc:date>
    </item>
  </channel>
</rss>

