- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Capturing Configuration changes to switches, firewalls etc.
waJesu
Path Finder
09-19-2024
05:03 AM
I am new to Splunk administration, and I need a query that captures changes to configuration of switches, firewalls, routers etc, in my environment
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
PickleRick

SplunkTrust
09-19-2024
05:13 AM
Splunk is _not_ an active monitoring solution. That's what you use - for example - rancid or some commercial tools for. But if you get logs from such tool (or have audit logs from your appliances telling you that change happened), you can search from that data. But it will depend on what data you have.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
waJesu
Path Finder
09-19-2024
05:58 AM
It's the query to search those logs that I am looking for.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
PickleRick

SplunkTrust
09-19-2024
06:21 AM
The "query" (or in Splunk terminology - search) you're looking for will depend on what data you have indexed in your Splunk.
