Getting Data In

Can Splunk do File Integrity Monitoring on its own in 2017?

worm929
Explorer

I'm not being able to find consice information, since every post just links to this DEPRECATED feature: docs.splunk.com/Documentation/Splunk/6.0/Data/Monitorchangestoyourfilesystem

I want to be able to log (and then alert) if a change is noticed in a file (usually implemented via scheduled hash checks, but it doesn't matter). Is that possible, or not any more and I would need to pay for other services for that feature?

The other doc that gets usually linked is this: docs.splunk.com/Documentation/Splunk/latest/Data/MonitorfilesystemchangesonWindows
but the instructions make it seem like I can't use a Universal Forwarder and I must have another full fledged installation of splunk enterprise?
also the instructions have a crucial step where they link to a Microsoft Doc, but that link is completely dead, so it's missing instructions.

Can someone please clarify all this mess for me? I would really appreciate it.

wongdsc
Engager

Hi, seems there's another way located at http://docs.splunk.com/Documentation/Splunk/7.1.1/Data/MonitorfilesystemchangesonWindows
to address the deprecated feature.
Cheers, Desmond.

wongdsc
Engager

Hi,
I did a quick find, and noticed version 7.1.0 provides a way .. and you may have a look at https://docs.splunk.com/Documentation/Splunk/7.1.0/Data/MonitorfilesystemchangesonWindows
Hope this helps.
Cheers, Desmond.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

How Edge Processor's Durable Queue Works

Edge Processor sits in one of the most consequential places in any Splunk pipeline: between your data sources ...