<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: monitor empty folder, alert when there is file in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/monitor-empty-folder-alert-when-there-is-file/m-p/186603#M3117</link>
    <description>&lt;P&gt;Hi newbiesplunk,&lt;/P&gt;

&lt;P&gt;I don't think that's possible in Splunk. If you setup a directory monitor Splunk will index all files in that directory except those which are excluded by &lt;CODE&gt;blacklisted&lt;/CODE&gt; ... but then again you will not be able to search for them in Splunk and therefore you will not be able to setup an alert.&lt;/P&gt;

&lt;P&gt;My suggestion: write a shell script which will be fired by cron and sends an email if there is something in this directory.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
    <pubDate>Tue, 03 Jun 2014 13:55:21 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2014-06-03T13:55:21Z</dc:date>
    <item>
      <title>monitor empty folder, alert when there is file</title>
      <link>https://community.splunk.com/t5/Alerting/monitor-empty-folder-alert-when-there-is-file/m-p/186602#M3116</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I wish to create an monitor folder alert such that it will trigger the alert when there is at least one file in the folder. I do not want to index any file that found in this folder. thks&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2014 13:17:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/monitor-empty-folder-alert-when-there-is-file/m-p/186602#M3116</guid>
      <dc:creator>newbiesplunk</dc:creator>
      <dc:date>2014-06-03T13:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: monitor empty folder, alert when there is file</title>
      <link>https://community.splunk.com/t5/Alerting/monitor-empty-folder-alert-when-there-is-file/m-p/186603#M3117</link>
      <description>&lt;P&gt;Hi newbiesplunk,&lt;/P&gt;

&lt;P&gt;I don't think that's possible in Splunk. If you setup a directory monitor Splunk will index all files in that directory except those which are excluded by &lt;CODE&gt;blacklisted&lt;/CODE&gt; ... but then again you will not be able to search for them in Splunk and therefore you will not be able to setup an alert.&lt;/P&gt;

&lt;P&gt;My suggestion: write a shell script which will be fired by cron and sends an email if there is something in this directory.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2014 13:55:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/monitor-empty-folder-alert-when-there-is-file/m-p/186603#M3117</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-06-03T13:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: monitor empty folder, alert when there is file</title>
      <link>https://community.splunk.com/t5/Alerting/monitor-empty-folder-alert-when-there-is-file/m-p/186604#M3118</link>
      <description>&lt;P&gt;thks, i dont really know how to write shell script but i believe splunk is  powerful app that can do this simple job thru some search or config, it just that i dont know how. Any other suggestion? thks&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2014 14:01:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/monitor-empty-folder-alert-when-there-is-file/m-p/186604#M3118</guid>
      <dc:creator>newbiesplunk</dc:creator>
      <dc:date>2014-06-03T14:01:25Z</dc:date>
    </item>
    <item>
      <title>Re: monitor empty folder, alert when there is file</title>
      <link>https://community.splunk.com/t5/Alerting/monitor-empty-folder-alert-when-there-is-file/m-p/186605#M3119</link>
      <description>&lt;P&gt;One of the Main functionalty of splunk relies on indexing human readable Data. I don't know of any Way of Not indexing something and do the usual splunk Magic on this nothing....&lt;/P&gt;</description>
      <pubDate>Tue, 03 Jun 2014 14:32:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/monitor-empty-folder-alert-when-there-is-file/m-p/186605#M3119</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-06-03T14:32:34Z</dc:date>
    </item>
  </channel>
</rss>

