From the course: Splunk for Security Analytics and Monitoring

Unlock the full course today

Join today to access over 24,900 courses taught by industry experts.

Monitoring Windows files

Monitoring Windows files

- [Instructor] Splunk can do so many things including the continuous monitoring of files and directories. We would do this because we want to detect any changes to those files or directories. Now, let's say that we've got a situation where we've got a website with a specific file or a set of files on it that we want to monitor. So if there are updates, we want to know about it by being able to search through our indexes in Splunk. Now, think about your environment. Do you have websites that you host that might have important files that you need to track changes for? It could be a file related to services or products that are available on the site. It could be a script that runs in the background on a website that's used for maintenance. Anything that you can think of that you might want to know if a change has been made to it, in terms of the file system. Well, in our case, we've got a sample website running on a…

Contents