<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alert on The Creation Of New Folders in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Alert-on-The-Creation-Of-New-Folders/m-p/77596#M12229</link>
    <description>&lt;P&gt;Many thanks for your reply.  As I am monitoring a folder for an application which has been installed on a Windows server, would you be able to confirm that I am updating the correct inputs.conf file to monitor for any changes.&lt;/P&gt;

&lt;P&gt;C:\Program Files\Splunk\etc\apps\launcher\local&lt;/P&gt;

&lt;P&gt;According to the document update the file in SPLUNK_HOME/etc/system/local/  When I open up this folder it only contains the name of the server.&lt;/P&gt;</description>
    <pubDate>Tue, 20 Sep 2011 15:12:40 GMT</pubDate>
    <dc:creator>itsomana</dc:creator>
    <dc:date>2011-09-20T15:12:40Z</dc:date>
    <item>
      <title>Alert on The Creation Of New Folders</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-on-The-Creation-Of-New-Folders/m-p/77594#M12227</link>
      <description>&lt;P&gt;There is an application running on a server that when an error occurs it creates a new folder. file.  I have splunk monitoring the root of the folder, however is there any way that I can get Splunk to alert me if a new folder is automatically created.  I cannot monitor for the files in the new folder as the files are always different.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2011 09:09:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-on-The-Creation-Of-New-Folders/m-p/77594#M12227</guid>
      <dc:creator>itsomana</dc:creator>
      <dc:date>2011-09-19T09:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: Alert on The Creation Of New Folders</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-on-The-Creation-Of-New-Folders/m-p/77595#M12228</link>
      <description>&lt;P&gt;You may want to consider using "fschange" instead of monitor.  This will (1) give you a specific event when a new directory is created, and (2) this could be a more natural fit for one-time generated crash dump files.  This means that splunk will perodically check for changed or new  files, but it will not be polling as agressivly as it would with a standard "monitor" input.&lt;/P&gt;

&lt;P&gt;You can also have control over weather or not you want to actually index the entire file, or if you just want to see that one was created (all depending on your desired use.)&lt;/P&gt;

&lt;P&gt;I would suggest you start by reading the &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/MonitorChangestoYourFileSystem"&gt;Monitor Changes to your file system&lt;/A&gt; docs.&lt;/P&gt;

&lt;HR /&gt;

&lt;P&gt;It would certainly be possible to look for the creation of new folders based on newly appearing sources in your index, but this would require (1) storing of state between your searches to know when something new appears, and (2) it would require some assumptions about the timestamps of your events and any indexing delays....  So yeah, it could be done, but I suspect that &lt;CODE&gt;fschange&lt;/CODE&gt; will be a more straightforward solution.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Sep 2011 14:34:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-on-The-Creation-Of-New-Folders/m-p/77595#M12228</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2011-09-19T14:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: Alert on The Creation Of New Folders</title>
      <link>https://community.splunk.com/t5/Alerting/Alert-on-The-Creation-Of-New-Folders/m-p/77596#M12229</link>
      <description>&lt;P&gt;Many thanks for your reply.  As I am monitoring a folder for an application which has been installed on a Windows server, would you be able to confirm that I am updating the correct inputs.conf file to monitor for any changes.&lt;/P&gt;

&lt;P&gt;C:\Program Files\Splunk\etc\apps\launcher\local&lt;/P&gt;

&lt;P&gt;According to the document update the file in SPLUNK_HOME/etc/system/local/  When I open up this folder it only contains the name of the server.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2011 15:12:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Alert-on-The-Creation-Of-New-Folders/m-p/77596#M12229</guid>
      <dc:creator>itsomana</dc:creator>
      <dc:date>2011-09-20T15:12:40Z</dc:date>
    </item>
  </channel>
</rss>

