<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Splunk Self Monitoring in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Self-Monitoring/m-p/100402#M21007</link>
    <description>&lt;P&gt;HOWEVER, our security team did like event hashing.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.4/Admin/Eventhashing"&gt;http://docs.splunk.com/Documentation/Splunk/4.3.4/Admin/Eventhashing&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 18 Apr 2013 21:46:26 GMT</pubDate>
    <dc:creator>I_am_Jeff</dc:creator>
    <dc:date>2013-04-18T21:46:26Z</dc:date>
    <item>
      <title>Splunk Self Monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Self-Monitoring/m-p/100399#M21004</link>
      <description>&lt;P&gt;My security people have asked if there is a self-monitoring capability in Splunk to track situations such as&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;A disgruntled employee does something
and tries to cover his track by&lt;BR /&gt;
modifying the log file &lt;STRONG&gt;and&lt;/STRONG&gt; the Splunk
index, either by editing or removal.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Fri, 25 Jan 2013 19:34:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Self-Monitoring/m-p/100399#M21004</guid>
      <dc:creator>I_am_Jeff</dc:creator>
      <dc:date>2013-01-25T19:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Self Monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Self-Monitoring/m-p/100400#M21005</link>
      <description>&lt;P&gt;By default Splunk monitors changes to $SPLUNK_HOME/etc/. Changes to the index and log files are probably best tracked with operating system level changes. You could use fschange, but it is deprecated and as such, won't be around forever. &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/FSChangelocal"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/FSChangelocal&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;However, in my opinion, operating system level tools(auditd) are preferable to something like fschange.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2013 19:39:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Self-Monitoring/m-p/100400#M21005</guid>
      <dc:creator>jbsplunk</dc:creator>
      <dc:date>2013-01-25T19:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Self Monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Self-Monitoring/m-p/100401#M21006</link>
      <description>&lt;P&gt;Yup.  I knew about fschange going away.  And it's always difficult to have the watcher watch itself in a meaningful and trusted way.  Thank you for your comments!&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2013 20:35:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Self-Monitoring/m-p/100401#M21006</guid>
      <dc:creator>I_am_Jeff</dc:creator>
      <dc:date>2013-01-25T20:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Splunk Self Monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Splunk-Self-Monitoring/m-p/100402#M21007</link>
      <description>&lt;P&gt;HOWEVER, our security team did like event hashing.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/4.3.4/Admin/Eventhashing"&gt;http://docs.splunk.com/Documentation/Splunk/4.3.4/Admin/Eventhashing&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Apr 2013 21:46:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Splunk-Self-Monitoring/m-p/100402#M21007</guid>
      <dc:creator>I_am_Jeff</dc:creator>
      <dc:date>2013-04-18T21:46:26Z</dc:date>
    </item>
  </channel>
</rss>

