<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why is FSChange (file system change monitor) a deprecated feature in Splunk 5.0? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107987#M22696</link>
    <description>&lt;P&gt;I fully agree with dabbank!&lt;/P&gt;</description>
    <pubDate>Tue, 27 Nov 2012 14:48:31 GMT</pubDate>
    <dc:creator>dvb</dc:creator>
    <dc:date>2012-11-27T14:48:31Z</dc:date>
    <item>
      <title>Why is FSChange (file system change monitor) a deprecated feature in Splunk 5.0?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107980#M22689</link>
      <description>&lt;P&gt;Why is FSChange a deprecated feature in Splunk 5.0? &lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2012 20:55:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107980#M22689</guid>
      <dc:creator>BP9906</dc:creator>
      <dc:date>2012-10-30T20:55:24Z</dc:date>
    </item>
    <item>
      <title>Re: Why is FSChange (file system change monitor) a deprecated feature in Splunk 5.0?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107981#M22690</link>
      <description>&lt;P&gt;The fschange input is deprecated in 5.0 for two reasons.&lt;/P&gt;

&lt;P&gt;First, it does not run predictably on all platforms. Since it has been that way for some time, many felt that was a form of 'implicit' deprecation. We prefer to be open whenever possible, so we decided the time had come to signal that this feature had too many caveats. &lt;/P&gt;

&lt;P&gt;Second, it does not do what is generally required for audit use cases, which is track the user/account making the change. Most OS/FS pairs provide high quality, out-of-the-box tools to do this already. In fact our guidance has been to use those tools in most cases, leaving little room for a Splunk-maintained feature. &lt;/P&gt;

&lt;P&gt;We are considering migrating the file metadata capabilities of fschange into monitor. That won't help the second point, but would be parity with fschange. If you would like to weigh in to support that, please file an enhancement request with our support team; both so we know your use case, and can get back to you personally.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Oct 2012 21:24:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107981#M22690</guid>
      <dc:creator>cervelli</dc:creator>
      <dc:date>2012-10-30T21:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why is FSChange (file system change monitor) a deprecated feature in Splunk 5.0?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107982#M22691</link>
      <description>&lt;P&gt;When is Splunk planning on dropping support for fschange completely?&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2012 18:42:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107982#M22691</guid>
      <dc:creator>responsys_cm</dc:creator>
      <dc:date>2012-10-31T18:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: Why is FSChange (file system change monitor) a deprecated feature in Splunk 5.0?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107983#M22692</link>
      <description>&lt;P&gt;There is no decision on when to remove fschange. The input will be supported for at least as long as 4.3.x is supported.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2012 20:04:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107983#M22692</guid>
      <dc:creator>cervelli</dc:creator>
      <dc:date>2012-10-31T20:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: Why is FSChange (file system change monitor) a deprecated feature in Splunk 5.0?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107984#M22693</link>
      <description>&lt;P&gt;How long is that? This slightly related a previous question I had. &lt;A href="http://splunk-base.splunk.com/answers/55847/splunk-support-and-end-of-life"&gt;http://splunk-base.splunk.com/answers/55847/splunk-support-and-end-of-life&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Oct 2012 21:24:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107984#M22693</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-10-31T21:24:52Z</dc:date>
    </item>
    <item>
      <title>Re: Why is FSChange (file system change monitor) a deprecated feature in Splunk 5.0?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107985#M22694</link>
      <description>&lt;P&gt;Per the support agreement, (&lt;A href="http://www.splunk.com/web_assets/pdfs/support/SplunkSupportAgreement.pdf"&gt;http://www.splunk.com/web_assets/pdfs/support/SplunkSupportAgreement.pdf&lt;/A&gt;) until the second major release (e.g. 6.0) or 24 months, whichever is more. As 4.3 went GA Jan 2012, that would mean Jan 2014.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Nov 2012 23:35:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107985#M22694</guid>
      <dc:creator>cervelli</dc:creator>
      <dc:date>2012-11-01T23:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: Why is FSChange (file system change monitor) a deprecated feature in Splunk 5.0?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107986#M22695</link>
      <description>&lt;P&gt;With a Splunk Universal Forwarder installed on most production machines already the fschange monitor is an easy-to-use approach to monitor changes of certain configuration files.&lt;BR /&gt;
Together with "fullEvent = true" you even get a full history. To implement the same functionality with OS out-of-the-box tools like Linux inotify is not quite as handy.&lt;BR /&gt;
If "most OS/FS pairs provide high quality" support for this, why is it so hard then to do this right in Splunk?&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;I hereby request to keep the fschange input in Splunk&lt;/STRONG&gt; and fix open issues instead of throwing in the towel.&lt;/P&gt;</description>
      <pubDate>Tue, 13 Nov 2012 08:12:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107986#M22695</guid>
      <dc:creator>dabbank</dc:creator>
      <dc:date>2012-11-13T08:12:23Z</dc:date>
    </item>
    <item>
      <title>Re: Why is FSChange (file system change monitor) a deprecated feature in Splunk 5.0?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107987#M22696</link>
      <description>&lt;P&gt;I fully agree with dabbank!&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2012 14:48:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107987#M22696</guid>
      <dc:creator>dvb</dc:creator>
      <dc:date>2012-11-27T14:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: Why is FSChange (file system change monitor) a deprecated feature in Splunk 5.0?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107988#M22697</link>
      <description>&lt;P&gt;Can I ask, if you've not already done so, that you log a case with Support to ensure that your request is counted in the official ER stats.  I'd encourage anyone that needs this functionality to do the same.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2012 15:30:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107988#M22697</guid>
      <dc:creator>ahattrell_splun</dc:creator>
      <dc:date>2012-11-27T15:30:49Z</dc:date>
    </item>
    <item>
      <title>Re: Why is FSChange (file system change monitor) a deprecated feature in Splunk 5.0?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107989#M22698</link>
      <description>&lt;P&gt;The decision has already been made as fschange is already deprecated in 5.0 -- miracles do happen and maybe Splunk will redo it and it will work as expected in a future release.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Jan 2013 01:17:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107989#M22698</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2013-01-25T01:17:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why is FSChange (file system change monitor) a deprecated feature in Splunk 5.0?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107990#M22699</link>
      <description>&lt;P&gt;Please note that if you want to monitor changes to file content (i.e. fullEvent = true), you can get better and more consistent results using a regular file &lt;CODE&gt;monitor://&lt;/CODE&gt; rather than fschange, by setting props.conf settings &lt;CODE&gt;CHECK_METHOD&lt;/CODE&gt; to &lt;CODE&gt;modtime&lt;/CODE&gt; (or &lt;CODE&gt;entire_md5&lt;/CODE&gt;). You should also set LINE_BREAKER to &lt;CODE&gt;(?!)&lt;/CODE&gt; or &lt;CODE&gt;(*FAIL)&lt;/CODE&gt;, but you need to do this for fschange as well.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Feb 2013 16:43:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107990#M22699</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2013-02-18T16:43:51Z</dc:date>
    </item>
    <item>
      <title>Re: Why is FSChange (file system change monitor) a deprecated feature in Splunk 5.0?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107991#M22700</link>
      <description>&lt;P&gt;I agree that this is a usefull feature and that we should keep it.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Sep 2013 14:18:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107991#M22700</guid>
      <dc:creator>fquintella</dc:creator>
      <dc:date>2013-09-18T14:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: Why is FSChange (file system change monitor) a deprecated feature in Splunk 5.0?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107992#M22701</link>
      <description>&lt;P&gt;This might be a good forward looking solution: &lt;A href="http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html"&gt;http://www.cyberciti.biz/tips/linux-audit-files-to-see-who-made-changes-to-a-file.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2015 14:36:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-is-FSChange-file-system-change-monitor-a-deprecated-feature/m-p/107992#M22701</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2015-03-24T14:36:09Z</dc:date>
    </item>
  </channel>
</rss>

