Monitoring Splunk

Can we track changes to a file

johnsasikumar
Path Finder

I have a file being monitored by universal forwarder and being indexed. can I monitor changes to the file. I do the new change will be indexed into Splunk.
But can we track if a user has removed a particular line, which user has made that change.
a good example would be a configuration file..What if a line was removed or added. can we track which user made the change or when it was removed or added.

Tags (1)
0 Karma

paulbannister
Communicator

Hi There,

There is a deprecated input method called "fschange" that monitors for file system changes which may provide what you are looking for, as I said it is being deprecated but still currently works for us, example inputs below:

[fschange:\YOUR_FILE_PATH]
fullEvent=true
pollPeriod=3600
recurse=true
sendEventMaxSize=100000
signedaudit=false
disabled=0

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

A Four-Part Event Series: Full Stack Observability For the AI Era

As AI reshapes applications, infrastructure, and the way teams operate, the traditional boundaries of ...

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...