IT Operations Discussions
All the up-time. All the nines.

monitor large file system access using monitor of inputs.conf or auditd?

shwu
Engager

We have Linux servers for providing file sharing services like Samba and NFS. We need to monitor the user access activities to the files in the shared file system.  Many posts of this community pointed to use Splunk's inputs.conf for monitoring file access. Some also pointed to using Linux's auditd to get the result. Currently our Splunk setting already collects data from audit.log. 

 What is the pro/con for using inputs.conf or auditd?

Thanks.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...