<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unathorized Linux folder deletion in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148224#M185369</link>
    <description>&lt;P&gt;Hi Ayn&lt;/P&gt;

&lt;P&gt;I am not seeing fschange is deprecated in latest version 6.2 &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.0/admin/inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.0/admin/inputsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;please correct me If I am wrong...&lt;/P&gt;</description>
    <pubDate>Wed, 10 Dec 2014 08:12:43 GMT</pubDate>
    <dc:creator>kml_uvce</dc:creator>
    <dc:date>2014-12-10T08:12:43Z</dc:date>
    <item>
      <title>Unathorized Linux folder deletion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148221#M185366</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I am new to Splunk and need to complete the below use case&lt;/P&gt;

&lt;P&gt;Files in a linux directory are regularly archived to different directory. File deletion in this directory needs to be monitored.&lt;/P&gt;

&lt;P&gt;Example directory: user/data/files   on a  Linux machine&lt;BR /&gt;
Splunk ver:6.1&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2014 06:20:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148221#M185366</guid>
      <dc:creator>ajeeshneelamkav</dc:creator>
      <dc:date>2014-12-10T06:20:08Z</dc:date>
    </item>
    <item>
      <title>Re: Unathorized Linux folder deletion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148222#M185367</link>
      <description>&lt;P&gt;use this in inputs.conf&lt;BR /&gt;
[fschange:&amp;lt;path&amp;gt;]&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.0/admin/inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.0/admin/inputsconf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2014 07:08:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148222#M185367</guid>
      <dc:creator>kml_uvce</dc:creator>
      <dc:date>2014-12-10T07:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unathorized Linux folder deletion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148223#M185368</link>
      <description>&lt;P&gt;fschange is deprecated. Recommended option is to use each OS's native mechanisms for auditing filesystem activity, like auditd in Linux.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2014 08:00:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148223#M185368</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2014-12-10T08:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: Unathorized Linux folder deletion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148224#M185369</link>
      <description>&lt;P&gt;Hi Ayn&lt;/P&gt;

&lt;P&gt;I am not seeing fschange is deprecated in latest version 6.2 &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.0/admin/inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.0/admin/inputsconf&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;please correct me If I am wrong...&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2014 08:12:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148224#M185369</guid>
      <dc:creator>kml_uvce</dc:creator>
      <dc:date>2014-12-10T08:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: Unathorized Linux folder deletion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148225#M185370</link>
      <description>&lt;P&gt;I have done it, how can retrieve this particular change using search query to create an alert ?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2014 10:38:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148225#M185370</guid>
      <dc:creator>ajeeshneelamkav</dc:creator>
      <dc:date>2014-12-10T10:38:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unathorized Linux folder deletion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148226#M185371</link>
      <description>&lt;P&gt;if a folder deletes from Linux or files deleted from a Linux folder, will be there any specific keyword?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2014 10:59:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148226#M185371</guid>
      <dc:creator>ajeeshneelamkav</dc:creator>
      <dc:date>2014-12-10T10:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: Unathorized Linux folder deletion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148227#M185372</link>
      <description>&lt;P&gt;how you done it , by using fschange /?&lt;BR /&gt;
see keywords related to you deletion event and write search :&lt;/P&gt;

&lt;P&gt;index=&amp;lt;indexname&amp;gt; "keywords" and then go to save as-&amp;gt; alert&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2014 11:00:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148227#M185372</guid>
      <dc:creator>kml_uvce</dc:creator>
      <dc:date>2014-12-10T11:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: Unathorized Linux folder deletion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148228#M185373</link>
      <description>&lt;P&gt;see in your events or send any event...&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2014 11:12:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148228#M185373</guid>
      <dc:creator>kml_uvce</dc:creator>
      <dc:date>2014-12-10T11:12:38Z</dc:date>
    </item>
    <item>
      <title>Re: Unathorized Linux folder deletion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148229#M185374</link>
      <description>&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.0/releasenotes/Deprecatedfeatures"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.0/releasenotes/Deprecatedfeatures&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2014 12:02:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148229#M185374</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2014-12-10T12:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: Unathorized Linux folder deletion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148230#M185375</link>
      <description>&lt;P&gt;hmmm, usually splunk gives any deprecated features in conf files also, but they have not given in inputs.conf for fschange, they need to change the doc for inputs.conf...  &lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2014 12:11:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148230#M185375</guid>
      <dc:creator>kml_uvce</dc:creator>
      <dc:date>2014-12-10T12:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: Unathorized Linux folder deletion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148231#M185376</link>
      <description>&lt;P&gt;No, "deprecated" does not mean "removed". The functionality is still there, but is due for removal, and the recommendation is to explore other options instead.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2014 13:26:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148231#M185376</guid>
      <dc:creator>Ayn</dc:creator>
      <dc:date>2014-12-10T13:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: Unathorized Linux folder deletion</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148232#M185377</link>
      <description>&lt;P&gt;yeah i am saying  that splunk always mentioned that features is deprecated in conf files doc also but here splunk has not mentioned&lt;/P&gt;</description>
      <pubDate>Wed, 10 Dec 2014 13:36:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Unathorized-Linux-folder-deletion/m-p/148232#M185377</guid>
      <dc:creator>kml_uvce</dc:creator>
      <dc:date>2014-12-10T13:36:10Z</dc:date>
    </item>
  </channel>
</rss>

