Getting Data In

Monitor File Activity on SMB Share

ericl42
Path Finder

I need to monitor all file reads, writes, deletes, etc. on a SMB share from a Windows server. In the past, I've just turned on full file auditing on the folder in question and used the Splunk Universal Forwarder to grab those events and it worked great. However, I'm not sure how to complete that with a SMB share.

I've looked at the forums and I see people referencing fschange but that appears to be been deprecated so I'd like to go the normal Windows logging route.

Questions

  • If I turn on file auditing on \smbshareserver\share1 and mount it to server1.company.com, would all of the file access attempts be logged to local Event Log even if another server mounts that share? I would think no and therefore defeats the purpose.
  • Does the Isilon storage have it's own log file that would write this somewhere else and I could grab it there?
  • Is there a better/easier solution to do this?

The whole goal is I need to fully monitor this SMB share from one location even though lots of computers and users could access it.

0 Karma

vulnfree
Explorer

I have the same question. Any help?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...