Monitoring Splunk

How do I fix fschange getting host = $decideOnStartup?

tm
Observer

Hi,

I know that there is an article about fschange depreciated, but it's still exists in splunk 9.x.x.

I was wondering if anyone has this issue where the host = $decideOnStartup when using fschange, and possible how to fix it. This only happened to fschange for me. 

Also, any insight on alternatives to fschange is appreciated it.

[fschange:/root/somefile]
disabled = false
index = fs_change
recurse = true
pollPeriod = 30
sourcetype = fs_change

 

thank you.

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...