Getting Data In

Using fschange to monitor files on linux server from windows splunk server

tasdienes
Engager

I have splunk running on windows. I want to monitor the /etc directory on a linux server with fschange. Is that possible?

How would I specify the path? [fschange://servername/etc] ?

How should I enable splunk (which runs under a Windows AD domain account) to read the files on the linux server? I could share them with samba, but splunk wouldn't know how to handle the login credentials...

Tags (3)
0 Karma

mzorzi
Splunk Employee
Splunk Employee


You might want to install a light forwarder in the linux server, sending the data to the Windows Indexer.

You can even decide to use a cross filesystem solution like samba, but I believe you will encounter all sorts permissions and performance problems

tasdienes
Engager

Thanks, I'll give that a try.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...