Alerting

How to set up an alert email to trigger whenever a file is updated or modified and include the changes in the email?

raby1996
Path Finder

Hi all,

I have a monitor set up which monitors the mod-time on a file and reindexes the new one if available. I would like to set up alerts so that whenever a file is "updated or modified" it sends an email, possibly with the changes in the email. I would use the unique problem number associated with each file as well as the queue that it is relevant to ( they are both fields) I.E.

Original File
______________________________________________________
John's Queue-

Problem Number- 1234

Problem Text-

The problem seems to be associated with a Disk Drive
________________________________________________________



    Modified File
    _______________________________________________________

    John's Queue-

    Problem Number- 1234

    Problem Text-

    The problem seems to be associated with a Disk Drive

    Update- The problem turned out to be the cable not the disk drive
    ______________________________________________________________________

This would trigger an alert that would send out an email which would hopefully send out either the new event or just the updated portion, if this is not possible than a simple alert would suffice. My end goal is to achieve one of the 3 scenarios listed below. Thank you in advance.

Email scenario 1
___________________________________________________________________

Hello John, problem numer 1234 has been modified, the changes are listed below

"Update- The problem turned out to be the cable not the disk drive"
_______________________________________________________________________

Email scenario 2
___________________________________________________________________

Hello John, problem numer 1234 has been modified, the updated event is listed below

John's Queue-

Problem Number- 1234

Problem Text-

The problem seems to be associated with a Disk Drive
Update- The problem turned out to be the cable not the disk drive
_______________________________________________________________________


Email scenario 3
___________________________________________________________________

Hello John, problem numer 1234 has been modified
_______________________________________________________________________
0 Karma

raby1996
Path Finder

It is configured to re-index if the mod_time changes, should i change it? Also the content comes in as one event, this contains the problem number and all the text and information associated with it.

0 Karma

somesoni2
Revered Legend

So you've configure crcSalt in inputs.conf to re-index the file if the content changes??
How are the event broken, does whole file content comes as one event OR each line as one event?

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...