Getting Data In

Using fschange to monitor files on linux server from windows splunk server

Engager

I have splunk running on windows. I want to monitor the /etc directory on a linux server with fschange. Is that possible?

How would I specify the path? [fschange://servername/etc] ?

How should I enable splunk (which runs under a Windows AD domain account) to read the files on the linux server? I could share them with samba, but splunk wouldn't know how to handle the login credentials...

Tags (3)
0 Karma

Splunk Employee
Splunk Employee


You might want to install a light forwarder in the linux server, sending the data to the Windows Indexer.

You can even decide to use a cross filesystem solution like samba, but I believe you will encounter all sorts permissions and performance problems

Engager

Thanks, I'll give that a try.

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!