I would like to know if it is possible to be alerted if a file is older then a specific time frame. We have files that are written down every 5 minutes. I would like to be alerted if the age of the file is in excess of 7 minutes.
Any input would be appreciated.
|metadata type=sources index=* | eval age=now()-recentTime | where age>420
This lists all the sources (files indexed in Splunk) which were last accessed 420 sec (7 min) ago. You can setup alert when this search returns rows.
You probably want something that checks _time vs _indexedtime.
... | eval diff = _indexedtime - _time | where diff > 5*60*1000