Getting Data In

Difference between monitor and fschange

Nicholas_Key
Splunk Employee
Splunk Employee

[1] May I know what are the differences between using monitor or fschange?

[2] Is there a documentation about fschange? If there isn't, how do I make use of it?

Tags (2)
1 Solution

Simeon
Splunk Employee
Splunk Employee

[link text][1]Monitor is intended to be the input method for live log files that you continuously write data to. The fschange input method is intended to monitor a change in the filesystem. A basic example for each item:

  • use monitor for a web log file or java app log file
  • use fschange for a system file or configuration file

For more details you can read the documentation here:

http://www.splunk.com/base/Documentation/latest/Admin/Monitorfilesanddirectories

http://www.splunk.com/base/Documentation/latest/Admin/Monitorchangestoyourfilesystem

View solution in original post

Simeon
Splunk Employee
Splunk Employee

[link text][1]Monitor is intended to be the input method for live log files that you continuously write data to. The fschange input method is intended to monitor a change in the filesystem. A basic example for each item:

  • use monitor for a web log file or java app log file
  • use fschange for a system file or configuration file

For more details you can read the documentation here:

http://www.splunk.com/base/Documentation/latest/Admin/Monitorfilesanddirectories

http://www.splunk.com/base/Documentation/latest/Admin/Monitorchangestoyourfilesystem

Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI! Discover how Splunk’s agentic AI ...

[Puzzles] Solve, Learn, Repeat: Dereferencing XML to Fixed-length events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Stay Connected: Your Guide to December Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...