Getting Data In

How does fschange poll?

joonradley
Path Finder

Hi,

I am trying to determine the impact of using fschange on a large number of files.

Does Splunk check the time stamp of each and every file in the subdirectory with every poll interval or does Splunk register callback functions with the OS for changes to the directory or files?

thx

Joon

Tags (1)
0 Karma

dwaddle
SplunkTrust
SplunkTrust

To my knowledge, Splunk does not (currently, as of 4.2) register with any filesystem event API. You should pretty much count on polling. Not all platforms have these APIs, and the APIs vary greatly from platform to platform.

It's possible that Splunk (the company) has these types of improvements to fschange in their roadmap/plan. You should submit an enhancement request to help raise the importance of such changes within the product.

Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...