Getting Data In

How does fschange poll?

joonradley
Path Finder

Hi,

I am trying to determine the impact of using fschange on a large number of files.

Does Splunk check the time stamp of each and every file in the subdirectory with every poll interval or does Splunk register callback functions with the OS for changes to the directory or files?

thx

Joon

Tags (1)
0 Karma

dwaddle
SplunkTrust
SplunkTrust

To my knowledge, Splunk does not (currently, as of 4.2) register with any filesystem event API. You should pretty much count on polling. Not all platforms have these APIs, and the APIs vary greatly from platform to platform.

It's possible that Splunk (the company) has these types of improvements to fschange in their roadmap/plan. You should submit an enhancement request to help raise the importance of such changes within the product.

Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...