Hi,
Splunk FSchange is deprecated. Is there another way to replicate information of what fschange does?
I wan to show events information like below:
Thu Apr 07 17:07:00 2016 action=add, path="c:\3082.txt", isdir=0, size=17734, gid=-1, uid=-1, modtime="Thu Apr 07 17:06:49 2016", mode="rwxrwxrwx"
↧