Monitoring Splunk

fschange monitoring /root/.ssh/authorized_keys2

JasonCzerak
Explorer

So I'm at a loss here.

.bashrc and .bash_profile are picked up just fine. however I can't get authorized_keys2 to be picked up unless I do something like /root/.ssh/* I wish to avoid known_hosts. I've tried just about everything can think of. What's weird is /root/.ssh/authorized_keys2 it self fails.

Ideas?

[fschange:/root/]
filters = root_wl,all_bl
fullEvent = true

[filter:whitelist:root_wl]

Key root files that should never change

regex1 = [^/]authorized_keys2
regex2 = [^/]
.bash_profile
regex3 = [^/]*.bashrc

[filter:blacklist:all_bl]
regex1 = .?

Tags (2)
0 Karma

MuS
Legend

Hi JasonCzerak

do you get any error in splunkd.log about this?
What happens if you add the file monitor in the UI Manager?

cheers

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...