Getting Data In

How does fschange poll?

joonradley
Path Finder

Hi,

I am trying to determine the impact of using fschange on a large number of files.

Does Splunk check the time stamp of each and every file in the subdirectory with every poll interval or does Splunk register callback functions with the OS for changes to the directory or files?

thx

Joon

Tags (1)
0 Karma

dwaddle
SplunkTrust
SplunkTrust

To my knowledge, Splunk does not (currently, as of 4.2) register with any filesystem event API. You should pretty much count on polling. Not all platforms have these APIs, and the APIs vary greatly from platform to platform.

It's possible that Splunk (the company) has these types of improvements to fschange in their roadmap/plan. You should submit an enhancement request to help raise the importance of such changes within the product.

Get Updates on the Splunk Community!

Accelerating Observability as Code with the Splunk AI Assistant

We’ve seen in previous posts what Observability as Code (OaC) is and how it’s now essential for managing ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...