
FSChange - local
Note: This feature has been deprecated in Splunk version 5.0. For a list of all deprecated features, see the topic "Deprecated features" in the Release Notes.
Splunk can be configured to monitor changes to your local file system as they occur. To do this, edit inputs.conf
and enable the fschange
scripted input. Once configured, Splunk will dutifully monitor any and all changes to the file system you specify.
More information on how to enable and configure the fschange
input can be found at "Monitor changes to your file system" in this manual.
PREVIOUS Unix logs - local |
NEXT WebSphere - local |
This documentation applies to the following versions of Splunk® Enterprise: 6.0, 6.0.1, 6.0.2, 6.0.3, 6.0.4, 6.0.5, 6.0.6, 6.0.7, 6.0.8, 6.0.9, 6.0.10, 6.0.11, 6.0.12, 6.0.13, 6.0.14, 6.0.15, 6.1, 6.1.1, 6.1.2, 6.1.3, 6.1.4, 6.1.5, 6.1.6, 6.1.7, 6.1.8, 6.1.9, 6.1.10, 6.1.11, 6.1.12, 6.1.13, 6.1.14
Feedback submitted, thanks!