<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NOOB - fschange setup not working in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/NOOB-fschange-setup-not-working/m-p/50837#M9747</link>
    <description>&lt;P&gt;Hi skopy&lt;/P&gt;

&lt;P&gt;you will love splunk the more you use it &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;does your user which runs splunkd have read access to /etc?&lt;BR /&gt;
what can be found if you search &lt;CODE&gt;index=_internal source="*splunkd.log*"&lt;/CODE&gt; for /etc?&lt;/P&gt;

&lt;P&gt;as you already have found answer.splunk.com; another great source is &lt;A href="http://docs.splunk.com/Documentation"&gt;splunk docs&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;cheers&amp;gt;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Jan 2012 15:08:35 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2012-01-13T15:08:35Z</dc:date>
    <item>
      <title>NOOB - fschange setup not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/NOOB-fschange-setup-not-working/m-p/50836#M9746</link>
      <description>&lt;P&gt;sorry for noob question, i am using splunk for 2 days...&lt;BR /&gt;
i am pulling my hair out, cant get it to work....&lt;/P&gt;

&lt;P&gt;i have setup an index fschange_test&lt;/P&gt;

&lt;P&gt;added this to local/inputs.conf&lt;/P&gt;

&lt;P&gt;[fschange:/etc] &lt;BR /&gt;
index = fschange_test&lt;BR /&gt;
recurse = true &lt;BR /&gt;
followLinks = false &lt;BR /&gt;
signedaudit = false &lt;BR /&gt;
fullEvent = true &lt;/P&gt;

&lt;P&gt;splunk restarted&lt;/P&gt;

&lt;P&gt;changed a few files, added some in /etc...&lt;/P&gt;

&lt;P&gt;so i go to search type  &lt;/P&gt;

&lt;P&gt;index="fschange_test"&lt;/P&gt;

&lt;P&gt;and get 0 matching events...&lt;BR /&gt;
the same goes if i add or change some files in splunks /etc dir whitch should work by default...&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2012 09:46:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/NOOB-fschange-setup-not-working/m-p/50836#M9746</guid>
      <dc:creator>skopy</dc:creator>
      <dc:date>2012-01-13T09:46:11Z</dc:date>
    </item>
    <item>
      <title>Re: NOOB - fschange setup not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/NOOB-fschange-setup-not-working/m-p/50837#M9747</link>
      <description>&lt;P&gt;Hi skopy&lt;/P&gt;

&lt;P&gt;you will love splunk the more you use it &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;does your user which runs splunkd have read access to /etc?&lt;BR /&gt;
what can be found if you search &lt;CODE&gt;index=_internal source="*splunkd.log*"&lt;/CODE&gt; for /etc?&lt;/P&gt;

&lt;P&gt;as you already have found answer.splunk.com; another great source is &lt;A href="http://docs.splunk.com/Documentation"&gt;splunk docs&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;cheers&amp;gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2012 15:08:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/NOOB-fschange-setup-not-working/m-p/50837#M9747</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2012-01-13T15:08:35Z</dc:date>
    </item>
    <item>
      <title>Re: NOOB - fschange setup not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/NOOB-fschange-setup-not-working/m-p/50838#M9748</link>
      <description>&lt;P&gt;i managed to get it running and currently running a battle with blacklist excluding folders on recurse, so i think i will have to go harder way; not to include what i want, but exclude what i dont want....&lt;/P&gt;

&lt;P&gt;thanks for your time to answer &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2012 15:31:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/NOOB-fschange-setup-not-working/m-p/50838#M9748</guid>
      <dc:creator>skopy</dc:creator>
      <dc:date>2012-01-13T15:31:18Z</dc:date>
    </item>
    <item>
      <title>Re: NOOB - fschange setup not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/NOOB-fschange-setup-not-working/m-p/50839#M9749</link>
      <description>&lt;P&gt;hi skopy, you could accept the answer so it will be marked as answered.....and have fun with splunk &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;MuS&amp;gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2012 15:38:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/NOOB-fschange-setup-not-working/m-p/50839#M9749</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2012-01-13T15:38:05Z</dc:date>
    </item>
  </channel>
</rss>

