Getting Data In

File and Directory Monitoring with Splunk

lohit
Path Finder

Hi all,

Since fschange is a deprecated feature post Splunk 5.0, i wwould like to know how to monitor windows and linu files/directories. For windows something comes to mind to enable auditing feature either as a GPO/local policy but nothing on linux. Please let me know what is the best possible approach to do this ?

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

For Linux you could use auditd to configure what to audit where, and Splunk the log from /var/log/audit/audit.log.

0 Karma
Get Updates on the Splunk Community!

The OpenTelemetry Certified Associate (OTCA) Exam

What’s this OTCA exam? The Linux Foundation offers the OpenTelemetry Certified Associate (OTCA) credential to ...

From Manual to Agentic: Level Up Your SOC at Cisco Live

Welcome to the Era of the Agentic SOC   Are you tired of being a manual alert responder? The security ...

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...