<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Auditing changes to Splunk configurations files related to users, adding/deleting files, receivers/forwarders .... in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Auditing-changes-to-Splunk-configurations-files-related-to-users/m-p/98680#M97529</link>
    <description>&lt;P&gt;I am trying to find out how much auditing is built-in in Splunk related to adding/deleting/updating&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Users &lt;/LI&gt;
&lt;LI&gt;Configuration (inputs.conf,outputs.conf)&lt;/LI&gt;
&lt;LI&gt;Parsing/processing (props.conf, transforms.con)&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;I added a new file or a new user, and tried to find out an audit event, but I could not find it in the internal indexes?&lt;/P&gt;

&lt;P&gt;May be I need to monitor all the Splunk config files?&lt;/P&gt;

&lt;P&gt;Thanks,
Jean&lt;/P&gt;</description>
    <pubDate>Fri, 03 Dec 2010 05:53:42 GMT</pubDate>
    <dc:creator>jdagenais</dc:creator>
    <dc:date>2010-12-03T05:53:42Z</dc:date>
    <item>
      <title>Auditing changes to Splunk configurations files related to users, adding/deleting files, receivers/forwarders ....</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Auditing-changes-to-Splunk-configurations-files-related-to-users/m-p/98680#M97529</link>
      <description>&lt;P&gt;I am trying to find out how much auditing is built-in in Splunk related to adding/deleting/updating&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;Users &lt;/LI&gt;
&lt;LI&gt;Configuration (inputs.conf,outputs.conf)&lt;/LI&gt;
&lt;LI&gt;Parsing/processing (props.conf, transforms.con)&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;I added a new file or a new user, and tried to find out an audit event, but I could not find it in the internal indexes?&lt;/P&gt;

&lt;P&gt;May be I need to monitor all the Splunk config files?&lt;/P&gt;

&lt;P&gt;Thanks,
Jean&lt;/P&gt;</description>
      <pubDate>Fri, 03 Dec 2010 05:53:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Auditing-changes-to-Splunk-configurations-files-related-to-users/m-p/98680#M97529</guid>
      <dc:creator>jdagenais</dc:creator>
      <dc:date>2010-12-03T05:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: Auditing changes to Splunk configurations files related to users, adding/deleting files, receivers/forwarders ....</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Auditing-changes-to-Splunk-configurations-files-related-to-users/m-p/98681#M97530</link>
      <description>&lt;P&gt;In current implementation, any changes made to the environment will not likely be logged within Splunk, certainly not in _internal et al. If you make changes via config files outside the UI or API, those things actions and changes can't be logged within Splunk.&lt;/P&gt;

&lt;P&gt;You can ingest the files themselves to compare _raw or even single line values, depending on your parsing preferences. However, it might be useful to have an external tool create hashes of all the files and store a log entry into Splunk with the hash, full path, and other metadata about the files. Then you can more easily report on changes to any of these files, including users.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jun 2015 17:37:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Auditing-changes-to-Splunk-configurations-files-related-to-users/m-p/98681#M97530</guid>
      <dc:creator>jtrucks</dc:creator>
      <dc:date>2015-06-16T17:37:15Z</dc:date>
    </item>
  </channel>
</rss>

