I have splunk running on windows. I want to monitor the /etc directory on a linux server with fschange. Is that possible?
How would I specify the path? [fschange://servername/etc] ?
How should I enable splunk (which runs under a Windows AD domain account) to read the files on the linux server? I could share them with samba, but splunk wouldn't know how to handle the login credentials...
... View more