Getting Data In

fschange not working in high load setups

strive
Influencer

Hi,

We have two kinds of setups. One setup for development where we inject ~2-5 GB data per day. Another one is for performance testing, where we inject ~75-100GB per day.

We have set fschange to $SPLUNK_HOME/etc/dep-apps directory. We have all our apps under this directory.

The pollPeriod is set to 180.

In our development setup fschange works fine. When something changes, the deployment server reloads and changes are pushed to other nodes.
Where as in performance testing setup it is not working.

What could be the reason? Is there any fix.

This is all we have in our inputs.conf for fschange.

[fschange:$SPLUNK_HOME/etc/dep-apps]
pollPeriod = 180

We are using splunk 4.3.1

Thanks

Strive

Tags (1)
0 Karma
1 Solution

miteshvohra
Contributor

Which version of Splunk are you using? According to the online documentation and release notes, 'fschange' monitor is deprecated in version 5.x.

HTH, Mitesh.

View solution in original post

0 Karma

miteshvohra
Contributor

Which version of Splunk are you using? According to the online documentation and release notes, 'fschange' monitor is deprecated in version 5.x.

HTH, Mitesh.

0 Karma

strive
Influencer

We are using 4.3.1

0 Karma
Get Updates on the Splunk Community!

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...

Operationalizing Entity Risk Score with Enterprise Security 8.3+

Overview Enterprise Security 8.3 introduces a powerful new feature called “Entity Risk Scoring” (ERS) for ...

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...