<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Trying to use FSChange for monitoring filesystem, getting a ton of sources and sourcetypes in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Trying-to-use-FSChange-for-monitoring-filesystem-getting-a-ton/m-p/78195#M19791</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I need to monitor a handful of application directories and system32 for changes.  I utilized FSChange with regex's to isolate file types to monitor.  I turned this on and all of a sudden I have over 100 sources and 30 sourcetypes!  Is there a way to make all of these under one source and sourcetype?  It appears each individual file is a different source type as opposed to a single fschange sourcetype.  &lt;/P&gt;

&lt;P&gt;Thanks for any help as there is so much its not very useful.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;

&lt;P&gt;Kevin&lt;/P&gt;</description>
    <pubDate>Wed, 27 Oct 2010 02:32:06 GMT</pubDate>
    <dc:creator>kholleran</dc:creator>
    <dc:date>2010-10-27T02:32:06Z</dc:date>
    <item>
      <title>Trying to use FSChange for monitoring filesystem, getting a ton of sources and sourcetypes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Trying-to-use-FSChange-for-monitoring-filesystem-getting-a-ton/m-p/78195#M19791</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I need to monitor a handful of application directories and system32 for changes.  I utilized FSChange with regex's to isolate file types to monitor.  I turned this on and all of a sudden I have over 100 sources and 30 sourcetypes!  Is there a way to make all of these under one source and sourcetype?  It appears each individual file is a different source type as opposed to a single fschange sourcetype.  &lt;/P&gt;

&lt;P&gt;Thanks for any help as there is so much its not very useful.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;

&lt;P&gt;Kevin&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2010 02:32:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Trying-to-use-FSChange-for-monitoring-filesystem-getting-a-ton/m-p/78195#M19791</guid>
      <dc:creator>kholleran</dc:creator>
      <dc:date>2010-10-27T02:32:06Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to use FSChange for monitoring filesystem, getting a ton of sources and sourcetypes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Trying-to-use-FSChange-for-monitoring-filesystem-getting-a-ton/m-p/78196#M19792</link>
      <description>&lt;P&gt;OK, I found the issue for the extra files I believe, it appears that in one of my whitelists I made a typo and forgot the opening bracket [.&lt;/P&gt;

&lt;P&gt;So hopefully it is limiting its monitoring to just .exe, .dll, etc   Is there a way to remove all those other sourcetypes and sources?  Also, can all fschange related events be under a single source and sourcetype called fschange?  Would I do this in transforms.conf?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2010 02:58:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Trying-to-use-FSChange-for-monitoring-filesystem-getting-a-ton/m-p/78196#M19792</guid>
      <dc:creator>kholleran</dc:creator>
      <dc:date>2010-10-27T02:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to use FSChange for monitoring filesystem, getting a ton of sources and sourcetypes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Trying-to-use-FSChange-for-monitoring-filesystem-getting-a-ton/m-p/78197#M19793</link>
      <description>&lt;P&gt;I also was pulling the whole event as I misunderstood what that did.  Now I have it working and apparently there is a bug where | delete does not get rid of the source &amp;amp; sourcetype so I have several hundred sources and sourcetypes that I don't want...&lt;/P&gt;</description>
      <pubDate>Tue, 09 Nov 2010 02:25:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Trying-to-use-FSChange-for-monitoring-filesystem-getting-a-ton/m-p/78197#M19793</guid>
      <dc:creator>kholleran</dc:creator>
      <dc:date>2010-11-09T02:25:25Z</dc:date>
    </item>
  </channel>
</rss>

