- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there a process I can use with Splunk Light to pull audit logs on how, who, when, and where directories are being created on our file share servers?
pnv2254
New Member
11-10-2015
10:39 AM
Is there a process I can use with Splunk to pull audit logs on how, who, when, and where directories are being created on our file share servers?
Thank you.
Steve
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
![jterry jterry](https://community.splunk.com/legacyfs/online/avatars/8124.jpg)
jterry
![Splunk Employee Splunk Employee](/html/@F88B7774A2BF2E9108D79A067A92A581/rank_icons/employee-16.png)
Splunk Employee
04-11-2016
10:15 AM
If the audit logs are already on disk/exist, it's easy. if not, it sounds like you need to look at scripted inputs.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
![jterry jterry](https://community.splunk.com/legacyfs/online/avatars/8124.jpg)
jterry
![Splunk Employee Splunk Employee](/html/@F88B7774A2BF2E9108D79A067A92A581/rank_icons/employee-16.png)
Splunk Employee
04-04-2016
05:04 PM
If the audit logs are already on disk/exist, it's easy. if not, it sounds like you need to look at scripted inputs.
![](/skins/images/53C7C94B4DD15F7CACC6D77B9B4D55BF/responsive_peak/images/icon_anonymous_message.png)