Lately I've been experiencing certain issues which indicates to me that changes are being made on some Linux systems. However, my Linux admin is denying making those changes and pointing the blame elsewhere. So I'd like to be able to track who is deleting/making changes to files/directories and/or the overall system itself. Thanks
Chances are you are not logging all changes to your Linux systems in Splunk. You may, however, be able to get the necessary information from the Linux audit log, if you're indexing it.
Hi richgalloway, what setting can I check to find out if I have the necessary configs in order to log Linux systems changes?
Look at the inputs.conf file(s) on the forwarders. What you see there will be all you have to work with.