All Apps and Add-ons

Monitoring a Remote Directory for Changes WITHOUT Ingesting files into Splunk?

New Member

HI All,

Long story short - I'm looking to monitor a remote directory for changes/new files/changes to files and send this information to Splunk. To re-emphasize, due to the nature of these files, I do NOT want to ingest the files themselves into Splunk. Metadata like, size, paths, owners, changes, etc. is what I am looking for.

I have discovered and set up Luke Murphey's "File/Directory Input" App -

However - After configuration, I'm not seeing anything come into Splunk...

M example path within this app on my Splunk Server (say is set to something like this for my remote server directory:

Is this app capable of doing that remotely?

Should this path be something like user@ip:/path/to/folder ? Wouldn't I need ssh keys of sorts to do this?


If this app isn't the solution...

Is a Universal Forwarder able to be configured to do this monitoring and forward metadata without forwarding the files themselves?


Thanks in advance for any help.

Labels (4)
0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...