I would like to know if it is possible to be alerted if a file is older then a specific time frame. We have files that are written down every 5 minutes. I would like to be alerted if the age of the file is in excess of 7 minutes.
Any input would be appreciated.
You probably want something that checks _time vs _indexedtime.
... | eval diff = _indexedtime - _time | where diff > 5*60*1000
|metadata type=sources index=* | eval age=now()-recentTime | where age>420
This lists all the sources (files indexed in Splunk) which were last accessed 420 sec (7 min) ago. You can setup alert when this search returns rows.