How to track if file size is 0 bytes 30 seconds after creation. Can anyone help me with this?
Thank you very much.
This can be done with some conditional logic.
This assumes you have a filed called Creation_time
which is in seconds AND have a field called bytes
| eval Creation_time_plus_thirty='Creation_time'+30
| eval time_after_creation=if(_time>'Creation_time_plus_thirty',1,0)
| eval ALERT=if(time_after_creation=1 AND bytes=0,"ALERT","GOOD")
| search ALERT="ALERT"
Thank you for your help.
But what search command do I have to use to get the file size if there is no field called bytes?
How are you currently calculating bytes? Do you have a GB, MB, or KB field?
No, there is no any field called bytes but I need to monitor the file size of a particular path.
I have tried with fschange stanza in inputs but it throws an error;
FSChangeMonitor - Monitoring file or directory that doesn't exist at startup time
How can I solve this?
Then how do you plan on doing this if you aren't monitoring the byte size? You should strongly consider these details before asking questions on here and wasting time