Monitoring Splunk

fschange monitoring /root/.ssh/authorized_keys2

JasonCzerak
Explorer

So I'm at a loss here.

.bashrc and .bash_profile are picked up just fine. however I can't get authorized_keys2 to be picked up unless I do something like /root/.ssh/* I wish to avoid known_hosts. I've tried just about everything can think of. What's weird is /root/.ssh/authorized_keys2 it self fails.

Ideas?

[fschange:/root/]
filters = root_wl,all_bl
fullEvent = true

[filter:whitelist:root_wl]

Key root files that should never change

regex1 = [^/]authorized_keys2
regex2 = [^/]
.bash_profile
regex3 = [^/]*.bashrc

[filter:blacklist:all_bl]
regex1 = .?

Tags (2)
0 Karma

MuS
Legend

Hi JasonCzerak

do you get any error in splunkd.log about this?
What happens if you add the file monitor in the UI Manager?

cheers

0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...