Monitoring Splunk

Is there any risk to monitor .sh or .bat files?

xiyangyang
Path Finder

Is there any risk to monitor .sh or .bat files?

Tags (1)
0 Karma

xiyangyang
Path Finder

I see. thank you

0 Karma

nickhills
Ultra Champion

Your welcome!
If my answer solved your problem, please be sure to accept it (and upvote if your feeling generous) as it helps others who visit in the future to know it solved your problem.

If my comment helps, please give it a thumbs up!
0 Karma

nickhills
Ultra Champion

No more risk than any other file which might contain code samples or naughty words.

Splunk wont ever execute them, and will process all inputs a plain text - the only risk is the content of the files, and whether you are happy to index the content of them (passwords, keys etc)

If my comment helps, please give it a thumbs up!

Yunagi
Communicator

When specifically monitoring source code files, I was thinking that [fschange] instead of [monitor] might be a good idea. However, now I am reading that fschange is deprecated. What are your thoughts?

0 Karma

nickhills
Ultra Champion

If your just looking to index the files when they change, you can use a normal monitor statement, and set CHECK_METHOD = entire_md5 in props.conf which will trigger Splunk to reindex the whole file each time it changes.
https://docs.splunk.com/Documentation/Splunk/7.0.1/Admin/Propsconf#File_checksum_configuration

If my comment helps, please give it a thumbs up!
0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese and ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...