Getting Data In

fschange not working in high load setups

strive
Influencer

Hi,

We have two kinds of setups. One setup for development where we inject ~2-5 GB data per day. Another one is for performance testing, where we inject ~75-100GB per day.

We have set fschange to $SPLUNK_HOME/etc/dep-apps directory. We have all our apps under this directory.

The pollPeriod is set to 180.

In our development setup fschange works fine. When something changes, the deployment server reloads and changes are pushed to other nodes.
Where as in performance testing setup it is not working.

What could be the reason? Is there any fix.

This is all we have in our inputs.conf for fschange.

[fschange:$SPLUNK_HOME/etc/dep-apps]
pollPeriod = 180

We are using splunk 4.3.1

Thanks

Strive

Tags (1)
0 Karma
1 Solution

miteshvohra
Contributor

Which version of Splunk are you using? According to the online documentation and release notes, 'fschange' monitor is deprecated in version 5.x.

HTH, Mitesh.

View solution in original post

0 Karma

miteshvohra
Contributor

Which version of Splunk are you using? According to the online documentation and release notes, 'fschange' monitor is deprecated in version 5.x.

HTH, Mitesh.

0 Karma

strive
Influencer

We are using 4.3.1

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...