Monitoring Splunk

Is there any risk to monitor .sh or .bat files?

xiyangyang
Path Finder

Is there any risk to monitor .sh or .bat files?

Tags (1)
0 Karma

xiyangyang
Path Finder

I see. thank you

0 Karma

nickhills
Ultra Champion

Your welcome!
If my answer solved your problem, please be sure to accept it (and upvote if your feeling generous) as it helps others who visit in the future to know it solved your problem.

If my comment helps, please give it a thumbs up!
0 Karma

nickhills
Ultra Champion

No more risk than any other file which might contain code samples or naughty words.

Splunk wont ever execute them, and will process all inputs a plain text - the only risk is the content of the files, and whether you are happy to index the content of them (passwords, keys etc)

If my comment helps, please give it a thumbs up!

Yunagi
Communicator

When specifically monitoring source code files, I was thinking that [fschange] instead of [monitor] might be a good idea. However, now I am reading that fschange is deprecated. What are your thoughts?

0 Karma

nickhills
Ultra Champion

If your just looking to index the files when they change, you can use a normal monitor statement, and set CHECK_METHOD = entire_md5 in props.conf which will trigger Splunk to reindex the whole file each time it changes.
https://docs.splunk.com/Documentation/Splunk/7.0.1/Admin/Propsconf#File_checksum_configuration

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Brains, Bytes, and Boston: Learn from the Best at .conf25

When you think of Boston, you might picture colonial charm, world-class universities, or even the crack of a ...

Splunk AppDynamics Agents Webinar Series

Mark your calendars! On June 24th at 12PM PST, we’re going live with the second session of our Splunk ...

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2025 SplunkTrust is officially open! If you ...