Alerting

set the alert to check file update or not

ajaynaralikar
New Member

Hi ,

I have to set alert the for below w requirement.
There is one file is present in my application and it is update continuously. So I have send the email alert when file is not update for 5 min. Is it possible in splunk?

Tags (1)
0 Karma

HiroshiSatoh
Champion

I think that it is good to acquire the audit event periodically using ”fschange”.

http://docs.splunk.com/Documentation/SplunkCloud/6.6.3/Data/Monitorchangestoyourfilesystem
※pollPeriod=N

0 Karma

ajaynaralikar
New Member

Hi ,

I didn't understand the document. Also I don't have the splunk server access so I can't check inputs.conf.file .
Is it possible through dashboard or custom search query.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...