Getting Data In

File System Monitoring

ESIMatNeforce
Path Finder

Hey,

I am trying to monitor changes to specific, sensitive folders on my samba file share. Therefore, the fschange feature seemed to be the perfect fit for me, but unfortunately it's not available anymore. Searching for an alternative, I did not really come across a suitable solution for monitoring file system changes on a samba file share.

What i want to know:
- Operation performed (read, write, delete)
- User
- Timestamp
- Optionally: Time a file is accessed
- Optionally: Restriced file access (users trying to access files/directories they arent permitted to access)

That's basically it, does anyone have a suitable solution for this issue?

Regards
Flo

0 Karma

kristian_kolb
Ultra Champion
0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 2)

Welcome to the "Splunk Classroom Chronicles" series, created to help curious, career-minded learners get ...

Index This | I am a number but I am countless. What am I?

January 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  Happy New Year! We’re ...

What’s New in Splunk Enterprise 9.4: Tools for Digital Resilience

PLATFORM TECH TALKS What’s New in Splunk Enterprise 9.4: Tools for Digital Resilience Thursday, February 27, ...