Getting Data In

fschange generates false update events

kkuminsky
Path Finder

I've set up file monitoring with fschange:

[fschange:C:\TEMP\test.txt]
index = main
recurse = false
followLinks = false
signedaudit = false
fullEvent = false
sendEventMaxSize = 1048576
delayInMills = 1000
pollPeriod = 60

What's happening is that every 60 seconds it generates update event. File is not modified. Modified time in all these events is the same.

6/10/10 3:28:09.000 PM Thu Jun 10 15:28:09 2010 action=update, path="C:\TEMP\test.txt", isdir=0, size=11, gid=-1, uid=-1, modtime="Thu Jun 10 15:10:32 2010", mode="rwxrwxrwx", hash=, chgs="modtime "

6/10/10 3:27:08.000 PM Thu Jun 10 15:27:08 2010 action=update, path="C:\TEMP\test.txt", isdir=0, size=11, gid=-1, uid=-1, modtime="Thu Jun 10 15:10:32 2010", mode="rwxrwxrwx", hash=, chgs="modtime "

6/10/10 3:26:07.000 PM Thu Jun 10 15:26:07 2010 action=update, path="C:\TEMP\test.txt", isdir=0, size=11, gid=-1, uid=-1, modtime="Thu Jun 10 15:10:32 2010", mode="rwxrwxrwx", hash=, chgs="modtime "

6/10/10 3:25:06.000 PM Thu Jun 10 15:25:06 2010 action=update, path="C:\TEMP\test.txt", isdir=0, size=11, gid=-1, uid=-1, modtime="Thu Jun 10 15:10:32 2010", mode="rwxrwxrwx", hash=, chgs="modtime "

6/10/10 3:24:05.000 PM Thu Jun 10 15:24:05 2010 action=update, path="C:\TEMP\test.txt", isdir=0, size=11, gid=-1, uid=-1, modtime="Thu Jun 10 15:10:32 2010", mode="rwxrwxrwx", hash=, chgs="modtime "

Any thoughts why it's happening?

0 Karma

maverick
Splunk Employee
Splunk Employee

This does not seem normal behavior for an fschange input.

Couple questions:

1) What version of Splunk are you running?

2) What version of Windows are you running Splunk on?

Also, try changing your file path to be the parent directory, instead of the test.txt file, like this and see if that makes any difference:

[fschange:C:\TEMP]
0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...