Monitoring Splunk

Best way to monitor for file transfer across multiple servers without indexing file contents

sssignals
Path Finder

Hi Splunk community

I need to monitor file transfers from servers to servers in different directories. I do not need to know the file content, only the time the file appear in each server as well as the file size. Eventually, we want to show if the number of files from source directory and destination directory tallies and is there a bottle neck in the file transfer process. Also, file transfers occur at anytime during the day, not at regular intervals. Appreciate your advice on my use case. Many thanks in advance.

Tags (1)
0 Karma

HiroshiSatoh
Champion

It is described by looking at the manual.

http://docs.splunk.com/Documentation/Splunk/7.1.2/Data/Monitorchangestoyourfilesystem

Monitor changes to your file system
This feature has been deprecated.

This feature has been deprecated as of Splunk Enterprise version 5.0. This means that although it continues to function in version 6.x of Splunk software, it might be removed in a future version. As an alternative, you can:
Learn how to monitor file system changes on Windows systems.
Use the auditd daemon on *nix systems and monitor output from the daemon.

※I am still using "fschange".

sssignals
Path Finder

Hi HiroshiSatoh

Does it mean that for multiple servers, i can run, say inotify to watch a directory, write the events to a log or logs and install a UF on each of these server to monitor these log/logs by forwarding to my indexer?

Is this the best approach?

Thanks in advance.

0 Karma

sssignals
Path Finder

How can I make the Indexer aware of inotify output when it is at a remote server? Thanks in advance for the help.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...