<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fschange deprecated; what options are available in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/fschange-deprecated-what-options-are-available/m-p/48951#M9291</link>
    <description>&lt;P&gt;Do you mean using Splunk exclusively, or do you want to know about other products that could solve this for you?&lt;/P&gt;</description>
    <pubDate>Thu, 29 Nov 2012 12:08:57 GMT</pubDate>
    <dc:creator>Ayn</dc:creator>
    <dc:date>2012-11-29T12:08:57Z</dc:date>
    <item>
      <title>fschange deprecated; what options are available</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/fschange-deprecated-what-options-are-available/m-p/48950#M9290</link>
      <description>&lt;P&gt;The 5.0 release documentation states that fschange is deprecated.&lt;/P&gt;

&lt;P&gt;We use this extensively for configuration change detection. Does anyone know of how to get the same functionality as fschange on Linux and Windows?&lt;/P&gt;

&lt;P&gt;Thx&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2012 11:56:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/fschange-deprecated-what-options-are-available/m-p/48950#M9290</guid>
      <dc:creator>joonradley</dc:creator>
      <dc:date>2012-11-29T11:56:56Z</dc:date>
    </item>
    <item>
      <title>Re: fschange deprecated; what options are available</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/fschange-deprecated-what-options-are-available/m-p/48951#M9291</link>
      <description>&lt;P&gt;Do you mean using Splunk exclusively, or do you want to know about other products that could solve this for you?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2012 12:08:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/fschange-deprecated-what-options-are-available/m-p/48951#M9291</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2012-11-29T12:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: fschange deprecated; what options are available</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/fschange-deprecated-what-options-are-available/m-p/48952#M9292</link>
      <description>&lt;P&gt;For Linux, I'd guess that the &lt;CODE&gt;auditd&lt;/CODE&gt; would be able to solve most things. Configuring it to be less noisy is probably an exercise. &lt;/P&gt;

&lt;P&gt;For Windows, I'd guess that you have to enable auditing on "object access", and set ACL's on the objects (files/directories) you wish to monitor. Exactly how to do this is a bit beyond my experience.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Nov 2012 12:19:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/fschange-deprecated-what-options-are-available/m-p/48952#M9292</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-11-29T12:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: fschange deprecated; what options are available</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/fschange-deprecated-what-options-are-available/m-p/48953#M9293</link>
      <description>&lt;P&gt;Any product will do at the moment.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Nov 2012 06:08:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/fschange-deprecated-what-options-are-available/m-p/48953#M9293</guid>
      <dc:creator>joonradley</dc:creator>
      <dc:date>2012-11-30T06:08:03Z</dc:date>
    </item>
    <item>
      <title>Re: fschange deprecated; what options are available</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/fschange-deprecated-what-options-are-available/m-p/48954#M9294</link>
      <description>&lt;P&gt;Can you pull in the entire configuration file with these methods?&lt;/P&gt;</description>
      <pubDate>Fri, 30 Nov 2012 06:08:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/fschange-deprecated-what-options-are-available/m-p/48954#M9294</guid>
      <dc:creator>joonradley</dc:creator>
      <dc:date>2012-11-30T06:08:38Z</dc:date>
    </item>
    <item>
      <title>Re: fschange deprecated; what options are available</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/fschange-deprecated-what-options-are-available/m-p/48955#M9295</link>
      <description>&lt;P&gt;Not too sure about that - or rather, I'm quite certain you can't. But what you will get is WHO made the change.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Nov 2012 07:35:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/fschange-deprecated-what-options-are-available/m-p/48955#M9295</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2012-11-30T07:35:20Z</dc:date>
    </item>
    <item>
      <title>Re: fschange deprecated; what options are available</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/fschange-deprecated-what-options-are-available/m-p/48956#M9296</link>
      <description>&lt;P&gt;Unfortunately I also need to track the changed contents as well.&lt;/P&gt;</description>
      <pubDate>Fri, 30 Nov 2012 10:56:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/fschange-deprecated-what-options-are-available/m-p/48956#M9296</guid>
      <dc:creator>joonradley</dc:creator>
      <dc:date>2012-11-30T10:56:25Z</dc:date>
    </item>
    <item>
      <title>Re: fschange deprecated; what options are available</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/fschange-deprecated-what-options-are-available/m-p/48957#M9297</link>
      <description>&lt;P&gt;TripWire does a good job of monitoring changes. Unsure if there is a ready made app for it.&lt;/P&gt;

&lt;P&gt;My two cents.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Apr 2013 11:00:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/fschange-deprecated-what-options-are-available/m-p/48957#M9297</guid>
      <dc:creator>miteshvohra</dc:creator>
      <dc:date>2013-04-11T11:00:33Z</dc:date>
    </item>
  </channel>
</rss>

