Getting Data In

fschange Alternatives

dgavic
Explorer

Does anyone know of another way to monitor folders/files in Windows other than fschange? I have played with the "monitor" stanza and WMI with very limited success. I have recently upgraded our infrastructure to Splunk 6, and with fschange being deprecated, I need to find an alternative to monitor file integrity.

Thank you in advance.

AdamRosen
New Member

STEALTHbits offers a file activity monitor and preconfigured Splunk dashboard https://splunkbase.splunk.com/app/3432/

0 Karma

dart
Splunk Employee
Splunk Employee

You could either use Window's built in auditing features or you could wrap Tim Golden's change monitoring python scripts into a modular input or scripted input.

Does this help you?

0 Karma

dgavic
Explorer

Hi dart,

Thank you for the response, but the Tim Golden's python script would not work for us. We need to monitor 6000+ endpoints in the field and installing python on each endpoint isn't an option. The other link you sent me was for fschange, and I am looking for alternatives to fschange, as fschange has been deprocated in Splunk 5.0.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...