Videos

  • Add Videos
  • View All

Latest Activity

Profile IconWilliam S and Please... Dee Esssss :-) joined splunkninja
1 hour ago
Amine Recoba is now a member of splunkninja
yesterday
Michael Wilde replied to Nikita's discussion Count failures and success via transaction
"How are these transactions linked together... by a field called "ID"?  If so.. just build them with the field ID, and then use one of the MV commands to extract a field with success or failure in it.   Paste some samples and…"
Friday
Linus Myrefelt updated their profile
May 22
Marie updated their profile
May 21
Marie is now a member of splunkninja
May 21
Profile IconJitter and matthew arguin joined splunkninja
May 18
Profile IconMatthew Carter and Nikita joined splunkninja
May 17
Hi All,

How to only send the full event in case of user/group or hash change but not time change of file in the scope of fschange?
As example:
[fschange:/etc/config.cfg]
fullEvent=true
sendEventMaxSize=-1
Now every time the file is touched, even without change, the complete content of the file is indexed.
In other words how to configure the [fschange] not to send ‘fullEvent’ in case of modtime change alone.

Thank you.
BR,
Stefan

Views: 96

Reply to This

Replies to This Discussion

Stefan..

What is happening to the file? Is someone opening the file and saving it, so the modtime's getting updated? Or is someone just reading the file?

Also.. which OS is it on?
Hi Michael,

Thanks for the response. The file is just being touched, as open and saved without being changed.
The hash in splunk desn't change however the complete file is indexed. When the files are really changed the hash changes and the file is indexed again.
My objective is to have the files indexed only when there is change in the content (hash)
The OS is AIX.

Regards,
Stefan

RSS

© 2012   Created by Michael Wilde.

Badges  |  Report an Issue  |  Terms of Service