Splunk FSchange is deprecated. Is there another way to replicate information of what fschange does?
I wan to show events information like below:
Thu Apr 07 17:07:00 2016 action=add, path="c:\3082.txt", isdir=0, size=17734, gid=-1, uid=-1, modtime="Thu Apr 07 17:06:49 2016", mode="rwxrwxrwx"
You can program a script to collect this information and index the output.
Hope i help you
you can use this App https://splunkbase.splunk.com/app/2776/ for this.
Hope this helps ...