Getting Data In

fschange generates false update events

kkuminsky
Path Finder

I've set up file monitoring with fschange:

[fschange:C:\TEMP\test.txt]
index = main
recurse = false
followLinks = false
signedaudit = false
fullEvent = false
sendEventMaxSize = 1048576
delayInMills = 1000
pollPeriod = 60

What's happening is that every 60 seconds it generates update event. File is not modified. Modified time in all these events is the same.

6/10/10 3:28:09.000 PM Thu Jun 10 15:28:09 2010 action=update, path="C:\TEMP\test.txt", isdir=0, size=11, gid=-1, uid=-1, modtime="Thu Jun 10 15:10:32 2010", mode="rwxrwxrwx", hash=, chgs="modtime "

6/10/10 3:27:08.000 PM Thu Jun 10 15:27:08 2010 action=update, path="C:\TEMP\test.txt", isdir=0, size=11, gid=-1, uid=-1, modtime="Thu Jun 10 15:10:32 2010", mode="rwxrwxrwx", hash=, chgs="modtime "

6/10/10 3:26:07.000 PM Thu Jun 10 15:26:07 2010 action=update, path="C:\TEMP\test.txt", isdir=0, size=11, gid=-1, uid=-1, modtime="Thu Jun 10 15:10:32 2010", mode="rwxrwxrwx", hash=, chgs="modtime "

6/10/10 3:25:06.000 PM Thu Jun 10 15:25:06 2010 action=update, path="C:\TEMP\test.txt", isdir=0, size=11, gid=-1, uid=-1, modtime="Thu Jun 10 15:10:32 2010", mode="rwxrwxrwx", hash=, chgs="modtime "

6/10/10 3:24:05.000 PM Thu Jun 10 15:24:05 2010 action=update, path="C:\TEMP\test.txt", isdir=0, size=11, gid=-1, uid=-1, modtime="Thu Jun 10 15:10:32 2010", mode="rwxrwxrwx", hash=, chgs="modtime "

Any thoughts why it's happening?

0 Karma

maverick
Splunk Employee
Splunk Employee

This does not seem normal behavior for an fschange input.

Couple questions:

1) What version of Splunk are you running?

2) What version of Windows are you running Splunk on?

Also, try changing your file path to be the parent directory, instead of the test.txt file, like this and see if that makes any difference:

[fschange:C:\TEMP]
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Keep the Learning Going with the New Best of .conf Hub

Hello Splunkers, With .conf26 getting closer, there’s already a lot of excitement building around this year’s ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

How to find the worst searches in your Splunk environment and how to fix them

Everyone knows Splunk is a powerful platform for running searches and doing data analytics. Your ...