Alerting

How to set up an alert email to trigger whenever a file is updated or modified and include the changes in the email?

raby1996
Path Finder

Hi all,

I have a monitor set up which monitors the mod-time on a file and reindexes the new one if available. I would like to set up alerts so that whenever a file is "updated or modified" it sends an email, possibly with the changes in the email. I would use the unique problem number associated with each file as well as the queue that it is relevant to ( they are both fields) I.E.

Original File
______________________________________________________
John's Queue-

Problem Number- 1234

Problem Text-

The problem seems to be associated with a Disk Drive
________________________________________________________



    Modified File
    _______________________________________________________

    John's Queue-

    Problem Number- 1234

    Problem Text-

    The problem seems to be associated with a Disk Drive

    Update- The problem turned out to be the cable not the disk drive
    ______________________________________________________________________

This would trigger an alert that would send out an email which would hopefully send out either the new event or just the updated portion, if this is not possible than a simple alert would suffice. My end goal is to achieve one of the 3 scenarios listed below. Thank you in advance.

Email scenario 1
___________________________________________________________________

Hello John, problem numer 1234 has been modified, the changes are listed below

"Update- The problem turned out to be the cable not the disk drive"
_______________________________________________________________________

Email scenario 2
___________________________________________________________________

Hello John, problem numer 1234 has been modified, the updated event is listed below

John's Queue-

Problem Number- 1234

Problem Text-

The problem seems to be associated with a Disk Drive
Update- The problem turned out to be the cable not the disk drive
_______________________________________________________________________


Email scenario 3
___________________________________________________________________

Hello John, problem numer 1234 has been modified
_______________________________________________________________________
0 Karma

raby1996
Path Finder

It is configured to re-index if the mod_time changes, should i change it? Also the content comes in as one event, this contains the problem number and all the text and information associated with it.

0 Karma

somesoni2
Revered Legend

So you've configure crcSalt in inputs.conf to re-index the file if the content changes??
How are the event broken, does whole file content comes as one event OR each line as one event?

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...