Splunk Search

Unathorized Linux folder deletion

ajeeshneelamkav
New Member

Hi All,

I am new to Splunk and need to complete the below use case

Files in a linux directory are regularly archived to different directory. File deletion in this directory needs to be monitored.

Example directory: user/data/files on a Linux machine
Splunk ver:6.1

Tags (2)
0 Karma

kml_uvce
Builder

use this in inputs.conf
[fschange:<path>]

http://docs.splunk.com/Documentation/Splunk/6.2.0/admin/inputsconf

kamal singh bisht
0 Karma

ajeeshneelamkav
New Member

if a folder deletes from Linux or files deleted from a Linux folder, will be there any specific keyword?

0 Karma

kml_uvce
Builder

see in your events or send any event...

kamal singh bisht
0 Karma

ajeeshneelamkav
New Member

I have done it, how can retrieve this particular change using search query to create an alert ?

0 Karma

kml_uvce
Builder

how you done it , by using fschange /?
see keywords related to you deletion event and write search :

index=<indexname> "keywords" and then go to save as-> alert

kamal singh bisht
0 Karma

Ayn
Legend

fschange is deprecated. Recommended option is to use each OS's native mechanisms for auditing filesystem activity, like auditd in Linux.

0 Karma

kml_uvce
Builder

Hi Ayn

I am not seeing fschange is deprecated in latest version 6.2 http://docs.splunk.com/Documentation/Splunk/6.2.0/admin/inputsconf

please correct me If I am wrong...

kamal singh bisht
0 Karma

Ayn
Legend
0 Karma

kml_uvce
Builder

hmmm, usually splunk gives any deprecated features in conf files also, but they have not given in inputs.conf for fschange, they need to change the doc for inputs.conf...

kamal singh bisht
0 Karma

Ayn
Legend

No, "deprecated" does not mean "removed". The functionality is still there, but is due for removal, and the recommendation is to explore other options instead.

0 Karma

kml_uvce
Builder

yeah i am saying that splunk always mentioned that features is deprecated in conf files doc also but here splunk has not mentioned

kamal singh bisht
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...