<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic File System Monitoring in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/File-System-Monitoring/m-p/155468#M31576</link>
    <description>&lt;P&gt;Hey,&lt;/P&gt;

&lt;P&gt;I am trying to monitor changes to specific, sensitive folders on my samba file share. Therefore, the fschange feature seemed to be the perfect fit for me, but unfortunately it's not available anymore. Searching for an alternative, I did not really come across a suitable solution for monitoring file system changes on a samba file share.&lt;/P&gt;

&lt;P&gt;What i want to know:&lt;BR /&gt;
 - Operation performed (read, write, delete)&lt;BR /&gt;
 - User&lt;BR /&gt;
 - Timestamp&lt;BR /&gt;
 - Optionally: Time a file is accessed&lt;BR /&gt;
 - Optionally: Restriced file access (users trying to access files/directories they arent permitted to access)&lt;/P&gt;

&lt;P&gt;That's basically it, does anyone have a suitable solution for this issue?&lt;/P&gt;

&lt;P&gt;Regards&lt;BR /&gt;
Flo&lt;/P&gt;</description>
    <pubDate>Mon, 25 Nov 2013 19:17:04 GMT</pubDate>
    <dc:creator>ESIMatNeforce</dc:creator>
    <dc:date>2013-11-25T19:17:04Z</dc:date>
    <item>
      <title>File System Monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/File-System-Monitoring/m-p/155468#M31576</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;

&lt;P&gt;I am trying to monitor changes to specific, sensitive folders on my samba file share. Therefore, the fschange feature seemed to be the perfect fit for me, but unfortunately it's not available anymore. Searching for an alternative, I did not really come across a suitable solution for monitoring file system changes on a samba file share.&lt;/P&gt;

&lt;P&gt;What i want to know:&lt;BR /&gt;
 - Operation performed (read, write, delete)&lt;BR /&gt;
 - User&lt;BR /&gt;
 - Timestamp&lt;BR /&gt;
 - Optionally: Time a file is accessed&lt;BR /&gt;
 - Optionally: Restriced file access (users trying to access files/directories they arent permitted to access)&lt;/P&gt;

&lt;P&gt;That's basically it, does anyone have a suitable solution for this issue?&lt;/P&gt;

&lt;P&gt;Regards&lt;BR /&gt;
Flo&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2013 19:17:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/File-System-Monitoring/m-p/155468#M31576</guid>
      <dc:creator>ESIMatNeforce</dc:creator>
      <dc:date>2013-11-25T19:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: File System Monitoring</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/File-System-Monitoring/m-p/155469#M31577</link>
      <description>&lt;P&gt;Perhaps either of these links may provide with guidance for a relevant tool;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://en.wikipedia.org/wiki/Integrity_checker" target="_blank"&gt;http://en.wikipedia.org/wiki/Integrity_checker&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://en.wikipedia.org/wiki/Samhain_%28software%29" target="_blank"&gt;http://en.wikipedia.org/wiki/Samhain_(software)&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://en.wikipedia.org/wiki/Comparison_of_file_verification_software" target="_blank"&gt;http://en.wikipedia.org/wiki/Comparison_of_file_verification_software&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://en.wikipedia.org/wiki/Tripwire_%28software%29" target="_blank"&gt;http://en.wikipedia.org/wiki/Tripwire_(software)&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you also want to record access &lt;EM&gt;attempts&lt;/EM&gt;, you may have to look into the audit daemon.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://security.blogoverflow.com/2013/01/a-brief-introduction-to-auditd/" target="_blank"&gt;http://security.blogoverflow.com/2013/01/a-brief-introduction-to-auditd/&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://xmodulo.com/2013/05/how-to-monitor-file-access-on-linux.html" target="_blank"&gt;http://xmodulo.com/2013/05/how-to-monitor-file-access-on-linux.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;/K&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 15:21:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/File-System-Monitoring/m-p/155469#M31577</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2020-09-28T15:21:48Z</dc:date>
    </item>
  </channel>
</rss>

