So I'm at a loss here.
.bashrc and .bash_profile are picked up just fine. however I can't get authorized_keys2 to be picked up unless I do something like /root/.ssh/* I wish to avoid known_hosts. I've tried just about everything can think of. What's weird is /root/.ssh/authorized_keys2 it self fails.
Ideas?
[fschange:/root/]
filters = root_wl,all_bl
fullEvent = true
[filter:whitelist:root_wl]
regex1 = [^/]authorized_keys2
regex2 = [^/].bash_profile
regex3 = [^/]*.bashrc
[filter:blacklist:all_bl]
regex1 = .?
Hi JasonCzerak
do you get any error in splunkd.log about this?
What happens if you add the file monitor in the UI Manager?
cheers