Getting Data In

fschange not working

gajananh999
Contributor

Dear All,

I am need to monitor a folder in which which all file are getting generated and which all the files get deleted at what all time all those things.
here is my syntax.

Am i making mistake here?

[fschange:D:\Test_logs\testingfschange\]

signedaudit = false

index = test

sourcetype = fschangeevents

Thanks

Gajanan Hiroji

0 Karma

rsennett_splunk
Splunk Employee
Splunk Employee

fschange has long been deprecated, so it is recommended that you take advantage of file system auditing on your chosen platform and let Splunk consume the audit information.

It appears that the file you wish to audit is on Windows... THIS article gives you the step by step info.

With Splunk... the answer is always "YES!". It just might require more regex than you're prepared for!
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...