I have changed input.conf and restarted Spulnk, but I can't see any event generated for changing /etc/hosts file.
The the procedure was
And the I coould find the fs change log. Am I missing any procedure?
=====================================
[root@splunk local]# pwd
/opt/splunk/etc/system/local
[root@splunk local]# cat inputs.conf
[default]
host = splunk
[fschange:/etc]
index=os
recurse=true
followLinks=true
pollPeriod=60
fullEvent=true
=====================Splunk Restarted
Are you searching for something like this?
index=os source="fschangemonitor" path=*hosts*
If that search doesn't return results, what Splunk & OS version are you using?