Getting Data In
Highlighted

Remote File Monitoring

Engager

Is there any way to monitor the attributes of files such as 'Date Created' or 'Modified Date' rather than modify the actual contents of the files? I am currently indexing the path to a shared folder on a remote server using the 'Files and Directories' data input and it is indexing the contents.

I am on Splunk ver. 4.1.3.

Tags (1)
Highlighted

Re: Remote File Monitoring

Splunk Employee
Splunk Employee

You should be able to use the file system change monitoring inputs:

http://www.splunk.com/base/Documentation/latest/Admin/Monitorchangestoyourfilesystem