<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fsmonitor question in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/fsmonitor-question/m-p/103156#M21665</link>
    <description>&lt;P&gt;oh. well you didn't say that. Does the file monitor not read in the file when it alerts you? I dont think you can do diff change monitoring from splunk. youd need a diff application to push the new copy to and the old copy then have splunk alert on what the diff application said changed. That would tell you but is a bunch of work. If the device is a network appliance, just use puppet or Cacti.&lt;/P&gt;</description>
    <pubDate>Mon, 22 Apr 2013 19:04:01 GMT</pubDate>
    <dc:creator>rnolette</dc:creator>
    <dc:date>2013-04-22T19:04:01Z</dc:date>
    <item>
      <title>fsmonitor question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/fsmonitor-question/m-p/103153#M21662</link>
      <description>&lt;P&gt;Is it possible for a file monitored with fsmonitor to send an alert on any difference of the file?  or would monitoring the file be able to provide that visibility.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2013 15:24:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/fsmonitor-question/m-p/103153#M21662</guid>
      <dc:creator>diegosainz</dc:creator>
      <dc:date>2013-04-22T15:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: fsmonitor question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/fsmonitor-question/m-p/103154#M21663</link>
      <description>&lt;P&gt;if fsmonitor has a log file that generates events on file status changes then you can write a custom  file monitor that will send the events to the splunk server. You then can create a realtime query Alert that will email you every time this event is triggered. I did this for checking when someone changes something on one of my servers that has a custom application on it.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2013 16:50:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/fsmonitor-question/m-p/103154#M21663</guid>
      <dc:creator>rnolette</dc:creator>
      <dc:date>2013-04-22T16:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: fsmonitor question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/fsmonitor-question/m-p/103155#M21664</link>
      <description>&lt;P&gt;We have done that, we would like to know what has changed in the file.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2013 18:56:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/fsmonitor-question/m-p/103155#M21664</guid>
      <dc:creator>diegosainz</dc:creator>
      <dc:date>2013-04-22T18:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: fsmonitor question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/fsmonitor-question/m-p/103156#M21665</link>
      <description>&lt;P&gt;oh. well you didn't say that. Does the file monitor not read in the file when it alerts you? I dont think you can do diff change monitoring from splunk. youd need a diff application to push the new copy to and the old copy then have splunk alert on what the diff application said changed. That would tell you but is a bunch of work. If the device is a network appliance, just use puppet or Cacti.&lt;/P&gt;</description>
      <pubDate>Mon, 22 Apr 2013 19:04:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/fsmonitor-question/m-p/103156#M21665</guid>
      <dc:creator>rnolette</dc:creator>
      <dc:date>2013-04-22T19:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: fsmonitor question</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/fsmonitor-question/m-p/103157#M21666</link>
      <description>&lt;P&gt;Thank you.  I will do that.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Apr 2013 14:34:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/fsmonitor-question/m-p/103157#M21666</guid>
      <dc:creator>diegosainz</dc:creator>
      <dc:date>2013-04-23T14:34:59Z</dc:date>
    </item>
  </channel>
</rss>

