Getting Data In

N number of configuration change on one host

jshael
New Member

Query to detect over N number configuration changes on a certain host within specific duration.
Any help is greatly appreciated!

Tags (2)
0 Karma

jawaharas
Motivator

_audit index has file system changes info.

You can start with something like below and refine the search query accordingly to your requirement.

index=_audit action IN ("add","update","delete")
0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...