Getting Data In
Highlighted

Using fschange to monitor files on linux server from windows splunk server

Engager

I have splunk running on windows. I want to monitor the /etc directory on a linux server with fschange. Is that possible?

How would I specify the path? [fschange://servername/etc] ?

How should I enable splunk (which runs under a Windows AD domain account) to read the files on the linux server? I could share them with samba, but splunk wouldn't know how to handle the login credentials...

Tags (3)
0 Karma
Highlighted

Re: Using fschange to monitor files on linux server from windows splunk server

Splunk Employee
Splunk Employee


You might want to install a light forwarder in the linux server, sending the data to the Windows Indexer.

You can even decide to use a cross filesystem solution like samba, but I believe you will encounter all sorts permissions and performance problems

Highlighted

Re: Using fschange to monitor files on linux server from windows splunk server

Engager

Thanks, I'll give that a try.

0 Karma