Hi Malex27,
Typically, linux will write an entry into:
/var/log/messages
Whenever a USB device is plugged in or removed from the server. You can configure this to be manually monitored via a monitor stanza in your inputs.conf.
Alternatively, you can use the Splunk for Unix & Linux app to monitor the file and send the data to an Indexer for the purposes of reporting.
Hope this helps 🙂
Hi Malex27,
Typically, linux will write an entry into:
/var/log/messages
Whenever a USB device is plugged in or removed from the server. You can configure this to be manually monitored via a monitor stanza in your inputs.conf.
Alternatively, you can use the Splunk for Unix & Linux app to monitor the file and send the data to an Indexer for the purposes of reporting.
Hope this helps 🙂
Thanks R.Turk,
I guess the first one is the simpler way, I just need to figure out the search patterns.